USN-1018-1: OpenSSL vulnerability
18 November 2010
Releases
Packages
- openssl -
Details
Rob Hulswit discovered a race condition in the OpenSSL TLS server
extension parsing code when used within a threaded server. A remote
attacker could trigger this flaw to cause a denial of service
or possibly execute arbitrary code with application privileges.
(CVE-2010-3864)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 8.04
Ubuntu 10.10
Ubuntu 10.04
After a standard system update you need to reboot your computer to make
all the necessary changes.