![]() | Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition | ||
|
|
![]() |
||||||||||||||
Solution Type Technical Instruction Sure Solution 1943913.1 : Oracle Key Manager (OKM) - List of Security Vulnerabilities (CVE's) Resolved in OKM 2.5.3
In this Document
Applies to:Oracle Key Manager - Version 2.5.2 and laterInformation in this document applies to any platform. GoalWhat security vulnerabilities (CVE's) are included in Oracle Key Manager 2.5.3? SolutionOKM 2.5.3 includes OpenSSL 0.9.8za. This version of OpenSSL resolves the Common Vulnerabilities and Exposures (CVEs) listed below: CVES ADDRESSED IN OPENSSL THAT IS IN THIS RELEASE CVE-2010-5298 - SSL_MODE_RELEASE_BUFFERS session injection or denial of service
OKM 2.5.3 includes fixes for a GNU Bash bug commonly referred to as “Shellshock”. These fixes resolve the CVEs listed below: CVES ADDRESSED IN GNU BASH FIXES THAT ARE IN THIS RELEASE CVE-2010-6271 - GNU Bash processes trailing strings after function definitions in the values of environment variables Please refer to the following document for instructions on downloading Oracle Key Manager software: How to download Oracle Key Manager gui and firmware software (Doc ID 1369030.1) Attachments This solution has no attachment |
||||||||||||||
|