Number: AV16-153
Date: 26 September 2016
Purpose
The purpose of this advisory is to bring attention to OpenSSL security updates, intended to fix issues caused by patches released in OpenSSL’s previous security update (September 22 2016).
Assessment
Two specific vulnerability issues are addressed in this update; 1 critical and 1 moderate in severity.
Affected Versions: OpenSSL versions 1.1.0 and 1.0.2i.
CVE References: CVE-2016-6309, CVE-2016-7052.
Suggested action
CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.
OpenSSL 1.1.0 users should upgrade to 1.1.0b
OpenSSL 1.0.2i users should upgrade to 1.0.2j
References
https://www.openssl.org/news/secadv/20160926.txt
https://www.openssl.org/policies/secpolicy.html