[USN-2913-3] OpenSSL update

Marc Deslauriers marc.deslauriers at canonical.com
Wed Feb 24 17:40:01 UTC 2016


==========================================================================
Ubuntu Security Notice USN-2913-3
February 24, 2016

openssl update
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Updated OpenSSL packages are required for the USN-2913-1 update.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

USN-2913-1 removed 1024-bit RSA CA certificates from the ca-certificates
package. This update adds support for alternate certificate chains to the
OpenSSL package to properly handle the removal.

Original advisory details:

 The ca-certificates package contained outdated CA certificates. This update
 refreshes the included certificates to those contained in the 20160104
 package, including the removal of the SPI CA and CA certificates with
 1024-bit RSA keys.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libssl1.0.0                     1.0.1f-1ubuntu2.17

Ubuntu 12.04 LTS:
  libssl1.0.0                     1.0.1-4ubuntu5.34

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  http://www.ubuntu.com/usn/usn-2913-3
  http://www.ubuntu.com/usn/usn-2913-1
  https://launchpad.net/bugs/1528645

Package Information:
  https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.17
  https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.34


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20160224/81ed26ad/attachment.sig>


More information about the ubuntu-security-announce mailing list