Secunia Logo
 
Debian update for OpenSSL
Secunia Advisory: SA9888
Release Date: 2003-10-01
Popularity: 6,637 views

Critical:
Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0543
CVE-2003-0544


Description:
Debian has issued updated packages for OpenSSL. These fix two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system.

For more information:
SA9886

Solution:
Updated packages:

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat.../openssl/openssl_0.9.6c-2.woody.4.dsc
Size/MD5 checksum: 675 76da6f792eccfa0e219a0bb42296546f
http://security.debian.org/pool/updat.../o/openssl/openssl_0.9.6c.orig.tar.gz
Size/MD5 checksum: 2153980 c8261d93317635d56df55650c6aeb3dc
http://security.debian.org/pool/updat...nssl/openssl_0.9.6c-2.woody.4.diff.gz
Size/MD5 checksum: 44514 c07ae1f584c7a8bc4d0a821b8e6801ab

Architecture independent packages:

http://security.debian.org/pool/updat...enssl/ssleay_0.9.6c-2.woody.4_all.deb
Size/MD5 checksum: 970 734c96f61a7d7032584ce001811d99ce

Alpha architecture:

http://security.debian.org/pool/updat...libssl-dev_0.9.6c-2.woody.4_alpha.deb
Size/MD5 checksum: 1551438 add644f20298bb07dd2368f6139e03bd
http://security.debian.org/pool/updat...ibssl0.9.6_0.9.6c-2.woody.4_alpha.deb
Size/MD5 checksum: 571194 17117f28911fee940def4cc5a5168ebf
http://security.debian.org/pool/updat...sl/openssl_0.9.6c-2.woody.4_alpha.deb
Size/MD5 checksum: 736296 f571a65a29ea963e9f82b4a70cc61bbc

ARM architecture:

http://security.debian.org/pool/updat.../libssl0.9.6_0.9.6c-2.woody.4_arm.deb
Size/MD5 checksum: 474030 c34ae889a0b0b05d16ab071069886ee8
http://security.debian.org/pool/updat...l/libssl-dev_0.9.6c-2.woody.4_arm.deb
Size/MD5 checksum: 1357972 7b5efab549fcace562b1df40f58eb434
http://security.debian.org/pool/updat...nssl/openssl_0.9.6c-2.woody.4_arm.deb
Size/MD5 checksum: 729736 bea9047ba98358b5d843ec5502c08d14

HP Precision architecture:

http://security.debian.org/pool/updat.../libssl-dev_0.9.6c-2.woody.4_hppa.deb
Size/MD5 checksum: 1435088 64ec697612a1a8bb7ec02a8dfe0f082a
http://security.debian.org/pool/updat...libssl0.9.6_0.9.6c-2.woody.4_hppa.deb
Size/MD5 checksum: 564870 7c9f44efb6fbf092a4c6285438f4218f
http://security.debian.org/pool/updat...ssl/openssl_0.9.6c-2.woody.4_hppa.deb
Size/MD5 checksum: 741856 c593ae8279de436da67de14a147b991c

Intel IA-32 architecture:

http://security.debian.org/pool/updat...libssl0.9.6_0.9.6c-2.woody.4_i386.deb
Size/MD5 checksum: 461714 9c291cab723133eb1c7c2309540dd9e2
http://security.debian.org/pool/updat...ssl/openssl_0.9.6c-2.woody.4_i386.deb
Size/MD5 checksum: 721748 654531d126d43611b236964e691b67e2
http://security.debian.org/pool/updat.../libssl-dev_0.9.6c-2.woody.4_i386.deb
Size/MD5 checksum: 1289866 0b05581c2d1c03f72644737aa7c37fe9

Intel IA-64 architecture:

http://security.debian.org/pool/updat...ssl/openssl_0.9.6c-2.woody.4_ia64.deb
Size/MD5 checksum: 763482 0292998feaac6ea041d2d044305b7715
http://security.debian.org/pool/updat...libssl0.9.6_0.9.6c-2.woody.4_ia64.deb
Size/MD5 checksum: 711022 dbfc0819492111ff1b8040c4dc615d03
http://security.debian.org/pool/updat.../libssl-dev_0.9.6c-2.woody.4_ia64.deb
Size/MD5 checksum: 1615238 74a9e23d5f17d9a4f40120d1103bfeb2

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...ssl/openssl_0.9.6c-2.woody.4_m68k.deb
Size/MD5 checksum: 720358 293043604c8e259a058f5e1d5925a96e
http://security.debian.org/pool/updat...libssl0.9.6_0.9.6c-2.woody.4_m68k.deb
Size/MD5 checksum: 450572 5ebfb9bc4f0da2986373032213e22f3d
http://security.debian.org/pool/updat.../libssl-dev_0.9.6c-2.woody.4_m68k.deb
Size/MD5 checksum: 1266566 5d8c56beaaa413dd72d3cf90b5b30349

Big endian MIPS architecture:

http://security.debian.org/pool/updat...ssl/openssl_0.9.6c-2.woody.4_mips.deb
Size/MD5 checksum: 717764 d7019cf6cf0d6618f8789c8290697367
http://security.debian.org/pool/updat.../libssl-dev_0.9.6c-2.woody.4_mips.deb
Size/MD5 checksum: 1416184 09aa020367ef0d06e3e22e550ea12102
http://security.debian.org/pool/updat...libssl0.9.6_0.9.6c-2.woody.4_mips.deb
Size/MD5 checksum: 483650 3008bbee5c4f7f5faf344317c59e0d82

Little endian MIPS architecture:

http://security.debian.org/pool/updat...l/openssl_0.9.6c-2.woody.4_mipsel.deb
Size/MD5 checksum: 717060 3180c04a1cb7dd325b06496ca2bff71b
http://security.debian.org/pool/updat...ibssl-dev_0.9.6c-2.woody.4_mipsel.deb
Size/MD5 checksum: 1410226 35cc9bc327c59471f5a909878efdbb76
http://security.debian.org/pool/updat...bssl0.9.6_0.9.6c-2.woody.4_mipsel.deb
Size/MD5 checksum: 476638 bb83a9bfc07679fbe21aab5abd56256f

PowerPC architecture:

http://security.debian.org/pool/updat...bssl-dev_0.9.6c-2.woody.4_powerpc.deb
Size/MD5 checksum: 1386776 f379528eae7a157bd830ea43a371efe4
http://security.debian.org/pool/updat.../openssl_0.9.6c-2.woody.4_powerpc.deb
Size/MD5 checksum: 726638 45d8adac74a907263e7507f64fd3c3e3
http://security.debian.org/pool/updat...ssl0.9.6_0.9.6c-2.woody.4_powerpc.deb
Size/MD5 checksum: 502422 a386a0fdd637da29848219a1ca16eae1

IBM S/390 architecture:

http://security.debian.org/pool/updat...libssl0.9.6_0.9.6c-2.woody.4_s390.deb
Size/MD5 checksum: 510438 4044c7c34e45d3b9b7f3ef69eacae491
http://security.debian.org/pool/updat...ssl/openssl_0.9.6c-2.woody.4_s390.deb
Size/MD5 checksum: 731592 79fe91bb12f87b2dc05a4dff2aba1a10
http://security.debian.org/pool/updat.../libssl-dev_0.9.6c-2.woody.4_s390.deb
Size/MD5 checksum: 1326384 0352ce5cd87305074b2fdc91e78badca

Sun Sparc architecture:

http://security.debian.org/pool/updat...ibssl0.9.6_0.9.6c-2.woody.4_sparc.deb
Size/MD5 checksum: 484720 99bace5e1758b19404ef0ab618f37048
http://security.debian.org/pool/updat...libssl-dev_0.9.6c-2.woody.4_sparc.deb
Size/MD5 checksum: 1344194 2290093fa5e49278491fdbe03f14ab1a
http://security.debian.org/pool/updat...sl/openssl_0.9.6c-2.woody.4_sparc.deb
Size/MD5 checksum: 737150 28a4ebcf466e4c4d8aaa0afe974e9893


-- Debian GNU/Linux unstable alias sid --

Fixed in version 0.9.7c-1.

Original Advisory:
http://lists.debian.org/debian-securi...-security-announce-2003/msg00201.html

Other References:
SA9886:
http://secunia.com/advisories/9886/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 76 views
2. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 45 views
3. VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability // 33 views
4. SquirrelMail Malformed HTML Mail Message Script Insertion // 31 views
5. VMware ESX Server update for bzip2 // 28 views
6. WebGUI Executable Attachments Vulnerability // 27 views
7. Kolab Server ClamAV Multiple Vulnerabilities // 27 views
8. HP-UX Unspecified Local Denial of Service Vulnerability // 27 views
9. mvnForum Unspecified Cross-Site Scripting and Request Forgery // 26 views
10. Sunbyte e-Flower "id" SQL Injection Vulnerability // 25 views