Amazon Linux 1 Security Advisory: ALAS-2014-273
Advisory Release Date: 2014-01-14 15:56 Pacific
Advisory Updated Date: 2014-09-16 22:16 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
A flaw was found in the way OpenSSL determined which hashing algorithm to use when TLS protocol version 1.2 was enabled. This could possibly cause OpenSSL to use an incorrect hashing algorithm, leading to a crash of an application using the library. (CVE-2013-6449)
It was discovered that the Datagram Transport Layer Security (DTLS) protocol implementation in OpenSSL did not properly maintain encryption and digest contexts during renegotiation. A lost or discarded renegotiation handshake packet could cause a DTLS client or server using OpenSSL to crash. (CVE-2013-6450)
A NULL pointer dereference flaw was found in the way OpenSSL handled TLS/SSL protocol handshake packets. A specially crafted handshake packet could cause a TLS/SSL client using OpenSSL to crash. (CVE-2013-4353)
Affected Packages:
openssl
Issue Correction:
Run yum update openssl to update your system.
i686:
openssl-static-1.0.1e-4.55.amzn1.i686
openssl-perl-1.0.1e-4.55.amzn1.i686
openssl-1.0.1e-4.55.amzn1.i686
openssl-devel-1.0.1e-4.55.amzn1.i686
openssl-debuginfo-1.0.1e-4.55.amzn1.i686
src:
openssl-1.0.1e-4.55.amzn1.src
x86_64:
openssl-debuginfo-1.0.1e-4.55.amzn1.x86_64
openssl-1.0.1e-4.55.amzn1.x86_64
openssl-static-1.0.1e-4.55.amzn1.x86_64
openssl-perl-1.0.1e-4.55.amzn1.x86_64
openssl-devel-1.0.1e-4.55.amzn1.x86_64