All HowTo's Redhat, Fedora and CentOS Linux Scripting in Bash

OpenSSL urgent upgrade notice

The OpenSSL team have released an advisory to upgrade to version 1.1.0c.

Read the notice here: “https://www.openssl.org/news/secadv/20161110.txt”.

Redhat’s article can be found here: “https://access.redhat.com/security/cve/cve-2016-7054”.

Severity: High

TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS
attack by corrupting larger payloads. This can result in an OpenSSL crash. This
issue is not considered to be exploitable beyond a DoS.

OpenSSL 1.1.0 users should upgrade to 1.1.0c

Sadly Redhat doesn’t use the same version numbers as the OpenSSL team but according to the Redhat article above, RHEL 7 is not susceptible to this. I’d recommend to upgrade to the latest version anyway.

Leave a Reply

Your email address will not be published. Required fields are marked *