[USN-3628-1] OpenSSL vulnerability

Leonidas S. Barbosa leo.barbosa at canonical.com
Thu Apr 19 16:13:27 UTC 2018

Ubuntu Security Notice USN-3628-1
April 19, 2018

openssl vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS


OpenSSL could allow access to sensitve information.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools


Alejandro Cabrera Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis
Manuel Alvarez Tapia discovered that OpenSSL incorrectly handled RSA
key generation. An attacker could possibly use this issue to perform a
cache-timing attack and recover private RSA keys.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.10:
  libssl1.0.0                     1.0.2g-1ubuntu13.5

Ubuntu 16.04 LTS:
  libssl1.0.0                     1.0.2g-1ubuntu4.12

Ubuntu 14.04 LTS:
  libssl1.0.0                     1.0.1f-1ubuntu2.25

After a standard system update you need to reboot your computer to make
all the necessary changes.


Package Information:
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20180419/c18f9e5c/attachment.sig>

More information about the ubuntu-security-announce mailing list