Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Mandriva Security Update Fixes OpenSSL Code Execution Vulnerability

Title : Mandriva Security Update Fixes OpenSSL Code Execution Vulnerability
VUPEN ID : VUPEN/ADV-2007-4085
CVE ID : CVE-2007-4995
Rated as : High Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-12-05


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

A vulnerability has been identified in Mandriva, which could be exploited by attackers to cause a denial of service or potentially execute arbitrary code. This issue is caused by an error in OpenSSL. For additional information, see : VUPEN/ADV-2007-3156

Affected Products

Mandriva Linux 2007.0
Mandriva Linux 2007.1
Mandriva Linux 2008.0

Solution

Upgrade the affected packages :

Mandriva Linux 2007.0:
29b8ee6237c242e753d086635b7e5cbe 2007.0/i586/libopenssl0.9.8-0.9.8b-2.4mdv2007.0.i586.rpm
e0c95ca66571cd7143bff6e4c25b027a 2007.0/i586/libopenssl0.9.8-devel-0.9.8b-2.4mdv2007.0.i586.rpm
cdfeee7908dd612a55be9dfe76463f26 2007.0/i586/libopenssl0.9.8-static-devel-0.9.8b-2.4mdv2007.0.i586.rpm
0372a27cd2fbd7f742d2e516bed7e1e2 2007.0/i586/openssl-0.9.8b-2.4mdv2007.0.i586.rpm
e9afd585fa9767297b830b5a39b1c755 2007.0/SRPMS/openssl-0.9.8b-2.4mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
a4e123f19b83f50a9d6d07b5f8de1770 2007.0/x86_64/lib64openssl0.9.8-0.9.8b-2.4mdv2007.0.x86_64.rpm
3249d71ae70e88dd56a32779992305e6 2007.0/x86_64/lib64openssl0.9.8-devel-0.9.8b-2.4mdv2007.0.x86_64.rpm
3de284ee38d421db9e0e17fc2f21590e 2007.0/x86_64/lib64openssl0.9.8-static-devel-0.9.8b-2.4mdv2007.0.x86_64.rpm
513aeae7d510454807d195b1c4d5dd37 2007.0/x86_64/openssl-0.9.8b-2.4mdv2007.0.x86_64.rpm
e9afd585fa9767297b830b5a39b1c755 2007.0/SRPMS/openssl-0.9.8b-2.4mdv2007.0.src.rpm

Mandriva Linux 2007.1:
86e63fec6b9657748cc42e8362e97744 2007.1/i586/libopenssl0.9.8-0.9.8e-2.3mdv2007.1.i586.rpm
2c9543f02f824e684dcb0aa0fad5d84e 2007.1/i586/libopenssl0.9.8-devel-0.9.8e-2.3mdv2007.1.i586.rpm
b697526216ebaf30d80e2f7f3cf7aa61 2007.1/i586/libopenssl0.9.8-static-devel-0.9.8e-2.3mdv2007.1.i586.rpm
592011ab8eb3dd7e4aa840688c3b4ca5 2007.1/i586/openssl-0.9.8e-2.3mdv2007.1.i586.rpm
8104a922d5698d8289d000a39b2c4230 2007.1/SRPMS/openssl-0.9.8e-2.3mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64:
5c5d79ec812456e36b1cf6dee6bf4f37 2007.1/x86_64/lib64openssl0.9.8-0.9.8e-2.3mdv2007.1.x86_64.rpm
0f05616372680ef165b32c6c4b58e63f 2007.1/x86_64/lib64openssl0.9.8-devel-0.9.8e-2.3mdv2007.1.x86_64.rpm
f62edfc3bee2982f51895c953bc7928d 2007.1/x86_64/lib64openssl0.9.8-static-devel-0.9.8e-2.3mdv2007.1.x86_64.rpm
67b3f1e4a2d6f170c28a675cf2b75db5 2007.1/x86_64/openssl-0.9.8e-2.3mdv2007.1.x86_64.rpm
8104a922d5698d8289d000a39b2c4230 2007.1/SRPMS/openssl-0.9.8e-2.3mdv2007.1.src.rpm

Mandriva Linux 2008.0:
20491db3430fabf6e27844e96bd4284a 2008.0/i586/libopenssl0.9.8-0.9.8e-8.1mdv2008.0.i586.rpm
bb3685c8ff31f5d1ff2b05f07aabf4f8 2008.0/i586/libopenssl0.9.8-devel-0.9.8e-8.1mdv2008.0.i586.rpm
9a3d5debe8da358efe0e46b13ed0d8e6 2008.0/i586/libopenssl0.9.8-static-devel-0.9.8e-8.1mdv2008.0.i586.rpm
272dcfdd768169e374fe195be5c75f1a 2008.0/i586/openssl-0.9.8e-8.1mdv2008.0.i586.rpm
ac6a1a0ee09b5ee6e9f496d758e7f4c7 2008.0/SRPMS/openssl-0.9.8e-8.1mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
21185b1271dbf340b8a554ce233228b5 2008.0/x86_64/lib64openssl0.9.8-0.9.8e-8.1mdv2008.0.x86_64.rpm
d517a6325f26d0f8d0abe29bf6098b0f 2008.0/x86_64/lib64openssl0.9.8-devel-0.9.8e-8.1mdv2008.0.x86_64.rpm
421e8bd33abf4be23587d38e0d6abac4 2008.0/x86_64/lib64openssl0.9.8-static-devel-0.9.8e-8.1mdv2008.0.x86_64.rpm
fc6dff2056b1be3554024c9cfe10a2dd 2008.0/x86_64/openssl-0.9.8e-8.1mdv2008.0.x86_64.rpm
ac6a1a0ee09b5ee6e9f496d758e7f4c7 2008.0/SRPMS/openssl-0.9.8e-8.1mdv2008.0.src.rpm

References

http://www.vupen.com/english/advisories/2007/4085
http://archives.mandrivalinux.com/security-announce/2007-12/msg00005.php

ChangeLog

2007-12-05 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7


  >> 2009-05-12

     

  Microsoft Patched 14
  Office PowerPoint Flaws

 

  >> 2009-04-28

     

  Adobe Reader / Acrobat
  Vulnerabilities
Disclosed

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy