Index: vuln.xml =================================================================== --- vuln.xml (revision 434537) +++ vuln.xml (working copy) @@ -58,6 +58,43 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + openssl -- multiple DoS vulnerabilities + + + linux-c6-openssl + 1.0.1e_13 + + + linux-c7-openssl + 1.0.1e_3 + + + + +

Red Hat reports:

+
+

An integer underflow leading to an out of bounds read flaw was found in + OpenSSL. A remote attacker could possibly use this flaw to crash a 32-bit + TLS/SSL server or client using OpenSSL if it used the RC4-MD5 cipher suite.

+

A denial of service flaw was found in the way the TLS/SSL protocol defined + processing of ALERT packets during a connection handshake. A remote attacker + could use this flaw to make a TLS/SSL server consume an excessive amount of CPU + and fail to accept connections form other clients.

+
+ +
+ + https://rhn.redhat.com/errata/RHSA-2017-0286.html + 2017-3731 + 2016-8610 + + + 2017-02-20 + 2017-02-22 + +
+ fbsdmon -- information disclosure vulnerability