RHSA-2019:2471: Moderate: openssl security update
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.<br>Security Fix(es):<br><li> openssl: 0-byte record padding oracle (CVE-2019-1559)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2471?
The severity of RHSA-2019:2471 is considered moderate due to the potential impact of the 0-byte record padding oracle vulnerability.
How do I fix RHSA-2019:2471?
To fix RHSA-2019:2471, update the OpenSSL packages to version 1.0.1e-58.el6_10 or newer.
What is the main vulnerability addressed in RHSA-2019:2471?
The main vulnerability addressed in RHSA-2019:2471 is a 0-byte record padding oracle vulnerability (CVE-2019-1559) affecting OpenSSL.
Which OpenSSL versions are affected by RHSA-2019:2471?
OpenSSL versions prior to 1.0.1e-58.el6_10 are affected by RHSA-2019:2471.
Is RHSA-2019:2471 relevant for all OpenSSL installations?
RHSA-2019:2471 is relevant for OpenSSL installations specifically using the versions provided by Red Hat and the affected packages.