Rapid7 Vulnerability & Exploit Database

RHSA-2012:0060: openssl security update

Back to Search

RHSA-2012:0060: openssl security update



OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)and Transport Layer Security (TLS v1) protocols, as well as afull-strength, general purpose cryptography library.It was discovered that the Datagram Transport Layer Security (DTLS)protocol implementation in OpenSSL leaked timing information whenperforming certain operations. A remote attacker could possibly use thisflaw to retrieve plain text from the encrypted packets by using a DTLSserver as a padding oracle. (CVE-2011-4108)A double free flaw was discovered in the policy checking code in OpenSSL.A remote attacker could use this flaw to crash an application that usesOpenSSL by providing an X.509 certificate that has specially-craftedpolicy extension data. (CVE-2011-4109)An information leak flaw was found in the SSL 3.0 protocol implementationin OpenSSL. Incorrect initialization of SSL record padding bytes couldcause an SSL client or server to send a limited amount of possiblysensitive data to its SSL peer via the encrypted connection.(CVE-2011-4576)It was discovered that OpenSSL did not limit the number of TLS/SSLhandshake restarts required to support Server Gated Cryptography. A remoteattacker could use this flaw to make a TLS/SSL server using OpenSSL consumean excessive amount of CPU by continuously restarting the handshake.(CVE-2011-4619)All OpenSSL users should upgrade to these updated packages, which containbackported patches to resolve these issues. For the update to take effect,all services linked to the OpenSSL library must be restarted, or the systemrebooted.


  • redhat-upgrade-openssl
  • redhat-upgrade-openssl-devel
  • redhat-upgrade-openssl-perl

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center