AnNyung Official Homepage Home > Update [ 1.0 ]  

HOME
What is AnNyung
Documents
Packages System
White Paper
Download
Update
  . 2.x [RSS]
  . 1.3 [RSS]
  . 1.2 [RSS]
  . 1.1 [RSS]
  . 1.0 [RSS]
FAQ
Hardware
RoadMap
Gallery

  Go oops.org
  AnNyung banner 88x31

  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15
  AnNyung banner 80x15



openssl 보안 업데이트
Web Browser 로는 FTP 접속이 불가능 합니다.

문서번호 : 1118592282
업데이트 : 2005.06.13


상세내용

OpenSSL 프로젝트는 견고하고 상용 제품 수준의 품질을 갖추고 풍부한 기능을
갖는 오픈 소스 툴킷으로서 보안 소켓 계층(SSL v2/v3)과 전송 계층 보안(TLS v1)
프로토콜을 구현하고 있다.

CAN-2004-0975
CAN-2005-0109

Colin Percival reported a cache timing attack that could allow a malicious
local user to gain portions of cryptographic keys. The Common
Vulnerabilities and Exposures project (cve.mitre.org) assigned the name
CAN-2005-0109 to the issue. The OpenSSL library has been patched to add a
new fixed-window mod_exp implementation as default for RSA, DSA, and DH
private-key operations. This patch is designed to mitigate cache timing
and potentially related attacks.

A flaw was found in the way the der_chop script creates temporary files. It
is possible that a malicious local user could cause der_chop to overwrite
files (CAN-2004-0975). The der_chop script was deprecated and has been
removed from these updated packages. AnNyung LInux did not ship der_chop
and is therefore not vulnerable to this issue.


Autoupdates 지원 : 지원

update 패키지

  RPMS :

    . openssl-0.9.6g-8.i686.rpm
    . openssl-devel-0.9.6g-8.i686.rpm

  SRPMS :

    . openssl-0.9.6g-8.src.rpm

참고 :
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0109
https://rhn.redhat.com/errata/RHSA-2005-476.html



    



 Home > Update [ 1.0 ]

Copyright 2013 OOPS Development Organization 
LAST MODIFIED: 2013/02/16