CAN-2002-0656, CAN-2002-0655, and CAN-2002-0659

Freeman Donald-r21331 <[email protected]> Tue, 17 Sep 2002 17:45:02 -0700
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
Hello, I want to verify upgrading my Unix Apache Stronghold(version 3)from build 3017 to build 3019 will fix the issues below?

Thanks, Don

OpenSSL is a commercial-grade, full-featured, and Open Source toolkit which implements the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library. OpenSSL is commonly used in secure web servers based on Apache. A security audit of the OpenSSL code sponsored by DARPA found several buffer overflows which affect versions 0.9.7 and 0.9.6d and earlier. Of the problems found, those that directly affect Apache users include:

The SSLv3 session ID supplied to a client from a malicious server could be oversized and overrun a buffer. This issue looks to be remotely exploitable. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0656 to this issue.

Various buffers used for storing ASCII representations of integers were too small on 64 bit platforms. This issue may be exploitable The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0655 to this issue.

Portions of the SSL protocol data stream which include the lengths of structures which are being transferred may not be properly validated, allowing a malicious client to cause an application to crash or enter an infinite loop. It has not been verified if this issue could lead to further consequences such as remote code execution. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0659 to this issue.

Additional link of reference are:
CERT® Advisory CA-2002-27 Apache/mod_ssl Worm
http://www.cert.org/advisories/CA-2002-27.html
CIAC M-125: Apache/mod_ssl Worm
http://www.ciac.org/ciac/bulletins/m-125.shtml
CERT® Advisory CA-2002-23 Multiple Vulnerabilities In OpenSSL
http://www.cert.org/advisories/CA-2002-23.html


Don Freeman 
Systems Engineer 
Global Internet Platforms 
Office: 602-952-3519 
Cell: 602-803-4305 
Skytel Two-Way 800-313-9614 
Email: [email protected] <mailto:[email protected]>