OpenSSL Advisory – Multiple Vulnerabilities

Number: AV16-036
Date: 1 March 2016

Purpose

The purpose of this advisory is to bring attention to multiple security advisories released by OpenSSL.

Assessment

CCIRC is aware of eight recently disclosed vulnerabilities in OpenSSL, two of which are rated as high.

Affected versions: OpenSSL 0.9.8, 1.0.0, 1.0.1, 1.0.2

CVE References: CVE-2015-0293, CVE-2015-3197, CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-0800

Suggested Action

CCIRC recommends that system administrators test and deploy the vendor released updates to affected platforms accordingly.

OpenSSL 1.0.1 users should upgrade to 1.0.1s
OpenSSL 1.0.2 users should upgrade to 1.0.2g

References:

Date modified: