Mandrake Linux Security Advisory : openssl (MDKSA-2005:179)

medium Nessus Plugin ID 20039
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

Yutaka Oiwa discovered vulnerability potentially affects applications that use the SSL/TLS server implementation provided by OpenSSL.

Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, which is intended to work around various bugs in third- party software that might prevent interoperability. The SSL_OP_MSIE_SSLV2_RSA_PADDING option disables a verification step in the SSL 2.0 server supposed to prevent active protocol-version rollback attacks. With this verification step disabled, an attacker acting as a 'man in the middle' can force a client and a server to negotiate the SSL 2.0 protocol even if these parties both support SSL 3.0 or TLS 1.0. The SSL 2.0 protocol is known to have severe cryptographic weaknesses and is supported as a fallback only.
(CVE-2005-2969)

The current default algorithm for creating 'message digests' (electronic signatures) for certificates created by openssl is MD5.
However, this algorithm is not deemed secure any more, and some practical attacks have been demonstrated which could allow an attacker to forge certificates with a valid certification authority signature even if he does not know the secret CA signing key.

To address this issue, openssl has been changed to use SHA-1 by default. This is a more appropriate default algorithm for the majority of use cases. If you still want to use MD5 as default, you can revert this change by changing the two instances of 'default_md = sha1' to 'default_md = md5' in /usr/{lib,lib64}/ssl/openssl.cnf.
(CVE-2005-2946)

Solution

Update the affected packages.

Plugin Details

Severity: Medium

ID: 20039

File Name: mandrake_MDKSA-2005-179.nasl

Version: 1.19

Type: local

Published: 10/19/2005

Updated: 1/6/2021

Dependencies: ssh_get_info.nasl

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:lib64openssl0.9.7, p-cpe:/a:mandriva:linux:lib64openssl0.9.7-devel, p-cpe:/a:mandriva:linux:lib64openssl0.9.7-static-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.7, p-cpe:/a:mandriva:linux:libopenssl0.9.7-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.7-static-devel, p-cpe:/a:mandriva:linux:openssl, cpe:/o:mandrakesoft:mandrake_linux:10.1, cpe:/o:mandriva:linux:2006, x-cpe:/o:mandrakesoft:mandrake_linux:le2005

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 10/11/2005

Reference Information

CVE: CVE-2005-2946, CVE-2005-2969

MDKSA: 2005:179

CWE: 310