F-Secure Vulnerability Information :
|
|
|---|---|
|
[Summary]
| [Detailed Description]
| [Solution]
| [CVE Reference]
|
|
| Report ID: | SA30220 | ||
| Source: | Secunia | ||
| Date of Discovery: | 13.05.2008 | ||
| Criticality: | Urgent | ||
| Affects: | Debian GNU/Linux 4.0 |
||
| Compromise From: | From remote |
||
| Compromise Type: | DoS System access Security bypass |
||
|
Summary
|
|||
|---|---|---|---|
|
Debian has issued an update for OpenSSL. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system, and a security issue, which can lead to weak cryptographic key material. |
|||
|
|||
|
Detailed Description
|
|||
|
Debian has issued an update for OpenSSL. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system, and a security issue, which can lead to weak cryptographic key material. |
|||
|
|||
| Solution | |||
|
Apply updated packages and recreate all cryptographic key material (see vendor advisory for more information). Original Advisory: |
|||
|
|||
| CVE Reference | |||
|
CVE-2008-0166
CVE-2007-4995 CVE-2007-3108 |
|||
|
|||
| F-Secure Corporation | |||
