Fedora 20 Security Update: openssl-1.0.1e-41.fc20

Resolved Bugs
1180234 – CVE-2014-3571 openssl: DTLS segmentation fault in dtls1_get_record
1180239 – CVE-2015-0205 openssl: DH client certificates accepted without verification
1180189 – CVE-2015-0204 openssl: Only allow ephemeral RSA keys in export ciphersuites [fedora-all]
1180187 – CVE-2014-8275 openssl: Fix various certificate fingerprint issues
1181013 – CVE-2014-3571 CVE-2014-3570 CVE-2015-0205 CVE-2015-0206 openssl: various flaws [fedora-all]
1180235 – CVE-2015-0206 openssl: DTLS memory leak in dtls1_buffer_record
1180240 – CVE-2014-3570 openssl: Bignum squaring may produce incorrect results<br
Multiple low and moderate impact security issues fixed.

Leave a Reply