ClickCease CentOS 6 ELS: openssl package with the fix for several CVEs gradual rollout - TuxCare

Table of Contents

Join Our Popular Newsletter

Join 4,500+ Linux & Open Source Professionals!

2x a month. No spam.

CentOS 6 ELS: openssl package with the fix for several CVEs gradual rollout

by

September 13, 2021 - TuxCare PR Team

A new updated openssl package with the fix for several CVEs within CentOS 6 ELS has been scheduled for gradual rollout from our production repository.

 

Rollout slot: 3
Rolled out to: 0.1%
ETA for 100% rollout: September 21


CHANGELOG

openssl-1.0.1e-62.el6.cloudlinux.els

  • Fix handling ASN.1 string as NULL terminated leads to read buffer overrun (CVE-2021-3712)
  • Fix excessively large primes in DH key generation (CVE-2018-0732)
  • Fix RSA key generation cache timing vulnerability (CVE-2018-0737)
  • Fix stack overflow parsing recursive ASN.1 structure (CVE-2018-0739)
  • Fix out-of-bounds read (CVE-2017-3735)

UPDATE COMMAND

yum update openssl*

IMMEDIATE UPDATE (VIA BYPASS)

yum update openssl* --enablerepo=ELS6-rollout-3-bypass

 

Looking to automate vulnerability patching without kernel reboots, system downtime, or scheduled maintenance windows?

Become a TuxCare Guest Writer