CVE-2014-8275
Publication date 8 January 2015
Last updated 24 July 2024
Ubuntu priority
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
18.04 LTS bionic |
Fixed 1.0.1f-1ubuntu10
|
|
16.04 LTS xenial |
Fixed 1.0.1f-1ubuntu10
|
|
14.04 LTS trusty |
Fixed 1.0.1f-1ubuntu2.8
|
|
openssl098 | ||
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-2459-1
- OpenSSL vulnerabilities
- 12 January 2015