此内容没有您所选择的语言版本。
Chapter 5. Security Fixes
This update includes fixes for the following security related issues:
| ID | Impact | Summary |
|---|---|---|
| Moderate | ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries | |
| Moderate | openssl: Malicious server can send large prime to client during DH(E) TLS handshake causing the client to hang | |
| Low | openssl: timing side channel attack in the DSA signature algorithm | |
| Low | openssl: RSA key generation cache timing vulnerability in crypto/rsa/rsa_gen.c allows attackers to recover private keys | |
| Low | tomcat: XSS in SSI printenv | |
| Moderate | openssl: 0-byte record padding oracle | |
| Moderate | tomcat: local privilege escalation | |
| Low | tomcat: session fixation when using FORM authentication | |
| Important | Ghostcat - Apache Tomcat AJP File Read/Inclusion Vulnerability (CNVD-2020-10487) |