ALAS-2014-351


Amazon Linux 1 Security Advisory: ALAS-2014-351
Advisory Release Date: 2014-06-05 15:38 Pacific
Advisory Updated Date: 2014-09-19 10:19 Pacific
Severity: Important

Issue Overview:

It was found that OpenSSL clients and servers could be forced, via a specially crafted handshake packet, to use weak keying material for communication. A man-in-the-middle attacker could use this flaw to decrypt and modify traffic between a client and a server. (CVE-2014-0224)


Affected Packages:

openssl097a


Issue Correction:
Run yum update openssl097a to update your system.

New Packages:
i686:
    openssl097a-0.9.7a-12.1.9.amzn1.i686
    openssl097a-debuginfo-0.9.7a-12.1.9.amzn1.i686

src:
    openssl097a-0.9.7a-12.1.9.amzn1.src

x86_64:
    openssl097a-debuginfo-0.9.7a-12.1.9.amzn1.x86_64
    openssl097a-0.9.7a-12.1.9.amzn1.x86_64