[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 421-1] openssl security update

Package        : openssl
Version        : 0.9.8o-4squeeze23
CVE ID         : CVE-2015-3197

A malicious client can negotiate SSLv2 ciphers that have been disabled on the
server and complete SSLv2 handshakes even if all SSLv2 ciphers have been
disabled, provided that the SSLv2 protocol was not also disabled via

Additionally, when using a DHE cipher suite a new DH key will always be
generated for each connection.

This will be the last security update for the squeeze version of the package.
The 0.9.8 version is no longer supported and the squeeze LTS support will end
soon.  If you are using openssl you should upgrade to wheezy or preferably
jessie.  The version in those versions contain many security improvements.

Kurt Roeckx

Attachment: signature.asc
Description: PGP signature

Reply to: