gpp_maybe
Security update for openssl
SUSE-SLE-DESKTOP-12-2015-282
This update of openssl fixes the following security issues: - CVE-2015-4000 (bsc#931698) * The Logjam Attack / weakdh.org * reject connections with DH parameters shorter than 1024 bits * generates 2048-bit DH parameters by default - CVE-2015-1788 (bsc#934487) * Malformed ECParameters causes infinite loop - CVE-2015-1789 (bsc#934489) * Exploitable out-of-bounds read in X509_cmp_time - CVE-2015-1790 (bsc#934491) * PKCS7 crash with missing EnvelopedContent - CVE-2015-1792 (bsc#934493) * CMS verify infinite loop with unknown hash function - CVE-2015-1791 (bsc#933911) * race condition in NewSessionTicket - CVE-2015-3216 (bsc#933898) * Crash in ssleay_rand_bytes due to locking regression - fix a timing side channel in RSA decryption (bnc#929678)
-
Release DateJun 17 2015
-
ReferencesBugzilla: 931698, 933911, 926597, 934489, 933898, 934487, 929678, 934491, 934493
CVEs: CVE-2015-1789, CVE-2015-1788, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-3216, CVE-2015-4000 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Desktop 12 x86_64
-
Packageslibopenssl1_0_0
Secure Sockets and Transport Layer Securitylibopenssl1_0_0-32bit1.0.1i-25.1 lock rpm
Secure Sockets and Transport Layer Securityopenssl1.0.1i-25.1 lock rpm
Secure Sockets and Transport Layer Security1.0.1i-25.1 lock rpm lock src