ALAS-2014-350

Related Vulnerabilities: CVE-2014-0224  

It was found that OpenSSL clients and servers could be forced, via a specially crafted handshake packet, to use weak keying material for communication. A man-in-the-middle attacker could use this flaw to decrypt and modify traffic between a client and a server. (CVE-2014-0224)

ALAS-2014-350


Amazon Linux AMI Security Advisory: ALAS-2014-350
Advisory Release Date: 2014-06-05 15:38 Pacific
Advisory Updated Date: 2014-09-18 00:40 Pacific
Severity: Important

Issue Overview:

It was found that OpenSSL clients and servers could be forced, via a specially crafted handshake packet, to use weak keying material for communication. A man-in-the-middle attacker could use this flaw to decrypt and modify traffic between a client and a server. (CVE-2014-0224)


Affected Packages:

openssl098e


Issue Correction:
Run yum update openssl098e to update your system.

New Packages:
i686:
    openssl098e-debuginfo-0.9.8e-18.2.13.amzn1.i686
    openssl098e-0.9.8e-18.2.13.amzn1.i686

src:
    openssl098e-0.9.8e-18.2.13.amzn1.src

x86_64:
    openssl098e-debuginfo-0.9.8e-18.2.13.amzn1.x86_64
    openssl098e-0.9.8e-18.2.13.amzn1.x86_64