Vulnerability: OpenSSL vulnerability Publication date: 14 January 2010 Releases affected: 9.10, 9.04, 8.10, 8.04, 6.06 Package: openssl CVE ID: CVE-2009-4355 Description: OpenSSL did not correctly free unused memory in certain situations. This flaw could be triggered by a remote attacker in SSL services, leading to a denial of service. Update instructions: After upgrading the system, restart applications using OpenSSL, especially Apache. See the link provided for more details on obtaining fixes. Corrective versions: - 9.10 karmic: libssl0.9.8 - 0.9.8g-16ubuntu3.1 - 9.04 jaunty: libssl0.9.8 - 0.9.8g-15ubuntu3.4 - 8.10 intrepid: libssl0.9.8 - 0.9.8g-10.1ubuntu2.6 - 8.04 hardy: libssl0.9.8 - 0.9.8g-4ubuntu3.9 - 6.06 dapper: libssl0.9.8 - 0.9.8a-7ubuntu0.11