USN-884-1: OpenSSL vulnerability
14 January 2010
OpenSSL vulnerability
Releases
Packages
- openssl -
Details
It was discovered that OpenSSL did not correctly free unused memory in
certain situations. A remote attacker could trigger this flaw in services
that used SSL, causing the service to use all available system memory,
leading to a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 9.04
Ubuntu 8.10
Ubuntu 8.04
Ubuntu 6.06
After a standard system upgrade you need to restart any applications
using OpenSSL, especially Apache, to effect the necessary changes.