RHSA-2015:1197MediumCVSS 3.7
Red Hat Security Advisory: openssl security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2015-1789 — OpenSSL: out-of-bounds read in X509_cmp_time CVE-2015-1790 — OpenSSL: PKCS7 crash with missing EnvelopedContent CVE-2015-4000 — LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2015:1197
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://www.openssl.org/news/secadv_20150611.txt
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1223211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1228603
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1228604
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2015/rhsa-2015_1197.json