Amazon Linux 1 Security Advisory: ALAS-2014-350
Advisory Release Date: 2014-06-05 15:38 Pacific
Advisory Updated Date: 2014-09-18 00:40 Pacific
It was found that OpenSSL clients and servers could be forced, via a specially crafted handshake packet, to use weak keying material for communication. A man-in-the-middle attacker could use this flaw to decrypt and modify traffic between a client and a server. (CVE-2014-0224)
Affected Packages:
openssl098e
Issue Correction:
Run yum update openssl098e to update your system.
i686:
openssl098e-debuginfo-0.9.8e-18.2.13.amzn1.i686
openssl098e-0.9.8e-18.2.13.amzn1.i686
src:
openssl098e-0.9.8e-18.2.13.amzn1.src
x86_64:
openssl098e-debuginfo-0.9.8e-18.2.13.amzn1.x86_64
openssl098e-0.9.8e-18.2.13.amzn1.x86_64