OpenSSL Affected By Four More Security Vulnerabilities

Written by Michael Larabel in Free Software on 3 December 2015 at 11:25 AM EST. 13 Comments
FREE SOFTWARE
The OpenSSL project made public today four new security advisories. Three of the issues are considered of moderate severity while one is low.

One issue is about BN_mod_exp producing incorrect results on xx86_64, a certificate verify crash with missing PSS parameter, X509_ATTRIBUTE memoryl eak, and the low issue is a race condition handling PSK identify hint.

New versions of OpenSSL 0.9.8 and 1.0.0 series are released, but these are anticipated to be the last security fixes to be released in those series. Users are encouraged to upgrade.

More details via the OpenSSL.org security advisory.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week