RHSA-2019:3700: Low: openssl security, bug fix, and enhancement update
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.The following packages have been upgraded to a later upstream version: openssl (1.1.1c). (BZ#1643026)Security Fix(es): openssl: timing side channel attack in the DSA signature algorithm (CVE-2018-0734) openssl: timing side channel attack in the ECDSA signature generation (CVE-2018-0735) openssl: ChaCha20-Poly1305 with long nonces (CVE-2019-1543) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3700?
The severity of RHSA-2019:3700 is classified as moderate.
How do I fix RHSA-2019:3700?
To fix RHSA-2019:3700, upgrade the OpenSSL package to version 1.1.1c-2.el8 or later.
Which systems are affected by RHSA-2019:3700?
RHSA-2019:3700 affects systems using the OpenSSL package version prior to 1.1.1c-2.el8.
What is OpenSSL and why is it important in RHSA-2019:3700?
OpenSSL is a cryptography toolkit essential for implementing SSL and TLS protocols, thereby securing communications over computer networks.
Is there a specific platform mentioned in RHSA-2019:3700?
RHSA-2019:3700 specifically mentions the Red Hat Enterprise Linux 8 platform.