OpenSSL CVEs Mar-19-2015

Bug #1434194 reported by Erica Windisch
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
CirrOS
Fix Committed
Medium
Dr. Jens Harbott

Bug Description

OpenSSL 1.0.0j 10 May 2012

vulnerable to several vulnerabilities fixed in 1.0.0r.

https://www.openssl.org/news/secadv_20150319.txt
https://isc.sans.edu/diary/OpenSSL+Patch+Released/19485

Not marked security as these are public vulnerabilities and not part of an active embargo.

Revision history for this message
Dr. Jens Harbott (j-harbott) wrote :

This can be solved by using a buildroot that is recent enough, currently not yet available as a stable release, see the updates that I pushed in https://code.launchpad.net/~j-rosenboom-j/cirros/update-ipv6.

Changed in cirros:
status: New → In Progress
assignee: nobody → Dr. Jens Rosenboom (j-rosenboom-j)
Revision history for this message
Dr. Jens Harbott (j-harbott) wrote :

Looking at the buildroot config, it seems to me that we do not need openssl libraries at all. Probably they were added implicitly when compiling openssh, but not dropped again after moving to dropbear.

Revision history for this message
Scott Moser (smoser) wrote :

Aren't they used by curl ?

Revision history for this message
Scott Moser (smoser) wrote :

also, i think we're probably fix-committed in trunk now with update to buildroot.

Revision history for this message
Scott Moser (smoser) wrote :

marking as such, if you disagree please re-open.

Changed in cirros:
status: In Progress → Fix Committed
importance: Undecided → Medium
Revision history for this message
Erica Windisch (ewindisch) wrote :

Love to get a fix-released with this. Screenshot of the Docker Hub reminding users that this image might be vulnerable. This list is truncated, there are a LOT of vulnerabilities in this OpenSSL release.

(Objectively, I recognize that shipped binaries may not actually be using this openssl lib, but it may also be assumed that users may be using dynamic binaries linked to openssl)

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.