>> Redhat Security Update Fixes Two OpenSSL Vulnerabilities
Title : Redhat Security Update Fixes Two OpenSSL Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0674 CVE ID : CVE-2004-0975 - CVE-2005-0109 CWE ID : CWE-
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2005-06-02
Technical Description
Redhat has released a security patch to correct two vulnerabilities identified in OpenSSL. The first flaw was found in the way the "der_chop" script creates temporary files, which may be exploited by a malicious local user to overwrite arbitrary files. The second vulnerability resides in the Hyper-Threading technology, which may cause information to be disclosed to local users, allowing privilege escalation attacks.