Amazon Linux 1 Security Advisory: ALAS-2014-351
Advisory Release Date: 2014-06-05 15:38 Pacific
Advisory Updated Date: 2014-09-19 10:19 Pacific
It was found that OpenSSL clients and servers could be forced, via a specially crafted handshake packet, to use weak keying material for communication. A man-in-the-middle attacker could use this flaw to decrypt and modify traffic between a client and a server. (CVE-2014-0224)
Affected Packages:
openssl097a
Issue Correction:
Run yum update openssl097a to update your system.
i686:
openssl097a-0.9.7a-12.1.9.amzn1.i686
openssl097a-debuginfo-0.9.7a-12.1.9.amzn1.i686
src:
openssl097a-0.9.7a-12.1.9.amzn1.src
x86_64:
openssl097a-debuginfo-0.9.7a-12.1.9.amzn1.x86_64
openssl097a-0.9.7a-12.1.9.amzn1.x86_64