Debian Security Advisory
DSA-2931-1 openssl -- security update
- Date Reported:
- 18 May 2014
- Affected Packages:
- openssl
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-0198.
- More information:
-
It was discovered that incorrect memory handling in OpenSSL's do_ssl3_write() function could result in denial of service.
The oldstable distribution (squeeze) is not affected.
For the stable distribution (wheezy), this problem has been fixed in version 1.0.1e-2+deb7u9.
For the testing distribution (jessie), this problem has been fixed in version 1.0.1g-4.
For the unstable distribution (sid), this problem has been fixed in version 1.0.1g-4.
We recommend that you upgrade your openssl packages.