The OpenSSL 1.0.2d and OpenSSL 1.0.1p release, Fixed a security issue (cve-2015-1793).
Security level: High
Affected versions: OpenSSL 1.0.2c, 1.0.2b, 1.0.1n and 1.0.1o.
Vulnerability Description: Alternative chains certificate forgery (cve-2015-1793)
OpenSSL Security Advisory [9 Jul 2015]=======================================alternative Chains Certificate Forgery ( cve-2015-1793) ======================================================severity:highduring Certificate Verification , OpenSSL (starting from version 1.0.1n and1.0.2b) would attempt to find a alternative certificate chain if the Firstattem PT to build such a chain fails. An error in the implementation of thislogic can mean, that's attacker could cause certain checks on untrustedcertificates To being bypassed, such as the CA flag, enabling them to use a validleaf certificate to act as a CA and "issue" an invalid CE Rtificate. This issue would impact any application that verifies certificates INCLUDINGSSL/TLS/DTLS clients and SSL/TLS/DTLS servers U Sing client authentication. This issue affects OpenSSL versions 1.0.2c, 1.0.2b, 1.0.1n and 1.0.1o. OpenSSL 1.0.2B/1.0.2C users should upgrade to 1.0.2dOpenSSL 1.0.1n/1.0.1o users should upgrade to 1.0.1pThis issue was rep Orted to OpenSSL on 24th June by Adam Langley/davidbenjamin (GOOGLE/BORINGSSL). The fix was developed by the BORINGSSL project. Note====as per our previous announcements and our Release strategy (https://www.openssl.org/about/releasestrat.html), Support for OpenSSL versions1.0.0 and 0.9.8 would cease on 31st December 2015. No security updates for thesereleases'll be provided after that date. Users of these releases are advisedto upgrade. References==========url for this Security advisory:https://www.openssl.org/news/secadv_20150709.txtnote:the online Version of the advisory is updated with Additionaldetails over time. For details of the OpenSSL severity classifications please see:https://www.openssl.org/about/secpolicy.html
Download: http://www.openssl.org/source/
"Vulnerability" OpenSSL update