Ubuntu Information for VU#720951

OpenSSL TLS heartbeat extension read overflow discloses sensitive information

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

http://www.ubuntu.com/usn/usn-2165-1/

https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1304042

Addendum

Note that the version number reported by openssl does not reflect the patch level. To verify that the usn-2165-1 fixed versions are installed, run the following command

    dpkg -l openssl libssl* | cat
    and compare the reported version numbers with those listed in the advisory.

    If you have feedback, comments, or additional information about this vulnerability, please send us email.