EulerOS 2.0 SP3 : openssl110f (EulerOS-SA-2018-1434)
Low Nessus Plugin ID 119923
SynopsisThe remote EulerOS host is missing a security update.
DescriptionAccording to the version of the openssl110f packages installed, the EulerOS installation on the remote host is affected by the following vulnerability :
- A microprocessor side-channel vulnerability was found on SMT (e.g, Hyper-Threading) architectures. An attacker running a malicious process on the same core of the processor as the victim process can extract certain secret information.(CVE-2018-5407)
Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected openssl110f package.