CVE-2015-0293
Publication date 17 March 2015
Last updated 24 July 2024
Ubuntu priority
The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (s2_lib.c assertion failure and daemon exit) via a crafted CLIENT-MASTER-KEY message.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
18.04 LTS bionic |
Fixed 1.0.1f-1ubuntu11
|
|
16.04 LTS xenial |
Fixed 1.0.1f-1ubuntu11
|
|
14.04 LTS trusty |
Fixed 1.0.1f-1ubuntu2.11
|
|
openssl098 | ||
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
References
Related Ubuntu Security Notices (USN)
- USN-2537-1
- OpenSSL vulnerabilities
- 19 March 2015