Package name
openssl
Date
2014-01-17
Advisory ID
MDVSA-2014:007
Affected versions
MBS1 x86_64

Problem description

A vulnerability has been discovered and corrected in openssl:

The DTLS retransmission implementation in OpenSSL through 0.9.8y and
1.x through 1.0.1e does not properly maintain data structures for
digest and encryption contexts, which might allow man-in-the-middle
attackers to trigger the use of a different context by interfering
with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c
(CVE-2013-6450).

The updated packages have been patched to correct this issue.

Updated packages

MBS1 x86_64

 0a21492e02429e199dfc88e8d502de88  mbs1/x86_64/lib64openssl1.0.0-1.0.0k-1.1.mbs1.x86_64.rpm
 13eaad31a74bb167ce0d661eb25b5ca1  mbs1/x86_64/lib64openssl-devel-1.0.0k-1.1.mbs1.x86_64.rpm
 fca41114d79983a4d7600ba9a97cea3f  mbs1/x86_64/lib64openssl-engines1.0.0-1.0.0k-1.1.mbs1.x86_64.rpm
 acaf2f9638cf2bafeeb3a0aebc173e85  mbs1/x86_64/lib64openssl-static-devel-1.0.0k-1.1.mbs1.x86_64.rpm
 8d7142a0c95315a29de750e2e29f2174  mbs1/x86_64/openssl-1.0.0k-1.1.mbs1.x86_64.rpm 
 35c5ec534b80c03ae237526e75c52c18  mbs1/SRPMS/openssl-1.0.0k-1.1.mbs1.src.rpm

References