Oracle Solaris System Administration (MOSC)

MOSC Banner

Enquiry for reported CVE

edited Feb 19, 2015 10:05AM in Oracle Solaris System Administration (MOSC) 4 commentsAnswered

Hi,

My customer has a concern for the following CVE:

 

CVE-2014-3571 - DTLS segmentation fault in dtls1_get_record.

CVE-2015-0206 - DTLS memory leak in dtls1_buffer_record.

CVE-2014-3569 - no-ssl3 configuration sets method to NULL

CVE-2014-3572 - ECDHE silently downgrades to ECDH [Client]

CVE-2015-0204 - RSA silently downgrades to EXPORT_RSA [Client]

CVE-2015-0205 - DH client certificates accepted without verification [Server]

      CVE-2014-8275 - Certificate fingerprints can be modified

      CVE-2014-3570 - Bignum squaring may produce incorrect results

I have visited this doc 1448883.1 Reference Index of CVD IDs and Solaris Patches.

But not all the CVE can be found. Pls advise where to get the resolution for all the CVE then?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center