USN-3899-1: OpenSSL vulnerability
27 February 2019
OpenSSL could be made to expose sensitive information over the network.
- openssl - Secure Socket Layer (SSL) cryptographic library and tools
- openssl1.0 - Secure Socket Layer (SSL) cryptographic library and tools
Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain
applications incorrectly used OpenSSL and could be exposed to a padding
oracle attack. A remote attacker could possibly use this issue to decrypt
The problem can be corrected by updating your system to the following package versions:
After a standard system update you need to reboot your computer to make
all the necessary changes.
- USN-4376-2: libssl1.0.0-udeb, openssl, libssl-dev, libssl1.0.0, libcrypto1.0.0-udeb, libssl-doc