MNBSD-2014-13: OpenSSL POODLE and related vulnerabilities

Severity: Unknown

Affected Package: openssl

Summary: OpenSSL POODLE and related vulnerabilities

Description

OpenSSL was updated to add workarounds for the POODLE vulnerability (padding oracle on downgraded legacy encryption) reported by Google, along with additional OpenSSL fixes shipped in the same advisory. Impacts include information disclosure of plaintext via SSLv3 and denial of service.

Affected Versions

openssl

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2014-3513, CVE-2014-3566, CVE-2014-3567, CVE-2014-3568

Published: October 21, 2014
Last Modified: October 21, 2014