gpp_maybe Security update for openssl-1_1
SUSE-SLE-SAP-12-SP4-2021-954


This update for openssl-1_1 fixes the following security issue: * CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension but includes a signature_algorithms_cert extension, then a NULL pointer dereference will result, leading to a crash and a denial of service attack. OpenSSL TLS clients are not impacted by this issue. [bsc#1183852]

  • Release Date
    Mar 25 2021
  • References
    Bugzilla: 1183852
    CVEs: CVE-2021-3449
  • Type
    security
  • Severity
    important

cloud_download Downloads

SUSE Linux Enterprise Server for SAP Applications 12.4 ppc64le
  • Packages
    libopenssl1_1
    Secure Sockets and Transport Layer Security
    1.1.1d-2.33.1
    lock rpm
    openssl-1_1
    Secure Sockets and Transport Layer Security
    1.1.1d-2.33.1
    lock rpm
    lock src
SUSE Linux Enterprise Server for SAP Applications 12.4 x86_64
  • Packages
    libopenssl1_1
    Secure Sockets and Transport Layer Security
    1.1.1d-2.33.1
    lock rpm
    libopenssl1_1-32bit
    Secure Sockets and Transport Layer Security
    1.1.1d-2.33.1
    lock rpm
    openssl-1_1
    Secure Sockets and Transport Layer Security
    1.1.1d-2.33.1
    lock rpm
    lock src