OpenSSL urgent upgrade notice

The OpenSSL team have released an advisory to upgrade to version 1.1.0c.

Read the notice here: “”.

Redhat’s article can be found here: “”.

Severity: High

TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS
attack by corrupting larger payloads. This can result in an OpenSSL crash. This
issue is not considered to be exploitable beyond a DoS.

OpenSSL 1.1.0 users should upgrade to 1.1.0c

Sadly Redhat doesn’t use the same version numbers as the OpenSSL team but according to the Redhat article above, RHEL 7 is not susceptible to this. I’d recommend to upgrade to the latest version anyway.

