USN-750-1: OpenSSL vulnerability
30 March 2009
OpenSSL vulnerability
Releases
Packages
- openssl -
Details
It was discovered that OpenSSL did not properly validate the length of an
encoded BMPString or UniversalString when printing ASN.1 strings. If a user
or automated system were tricked into processing a crafted certificate, an
attacker could cause a denial of service via application crash in
applications linked against OpenSSL.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 8.10
Ubuntu 8.04
Ubuntu 7.10
Ubuntu 6.06
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.