shield
Security update for openssl
SUSE-SLE-SDK-12-SP2-2017-228
This update for openssl fixes the following issues contained in the OpenSSL Security Advisory [26 Jan 2017] (bsc#1021641) Security issues fixed: - CVE-2016-7055: The x86_64 optimized montgomery multiplication may produce incorrect results (bsc#1009528) - CVE-2017-3731: Truncated packet could crash via OOB read (bsc#1022085) - CVE-2017-3732: BN_mod_exp may produce incorrect results on x86_64 (bsc#1022086) - Degrade the 3DES cipher to MEDIUM in SSLv2 (bsc#1001912) Non-security issues fixed: - fix crash in openssl speed (bsc#1000677) - fix X509_CERT_FILE path (bsc#1022271) - AES XTS key parts must not be identical in FIPS mode (bsc#1019637)
-
Release DateFeb 10 2017
-
ReferencesBugzilla: 1022271, 1022086, 1001912, 1022085, 1009528, 1021641, 1000677, 1019637
CVEs: CVE-2016-7055, CVE-2017-3731, CVE-2017-3732 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Software Development Kit 12.2 aarch64
-
Packageslibopenssl-devel
Include Files and Libraries mandatory for Developmentopenssl1.0.2j-59.1 lock rpm
Secure Sockets and Transport Layer Security1.0.2j-59.1 lock src
SUSE Linux Enterprise Software Development Kit 12.2 ppc64le
-
Packageslibopenssl-devel
Include Files and Libraries mandatory for Developmentopenssl1.0.2j-59.1 lock rpm
Secure Sockets and Transport Layer Security1.0.2j-59.1 lock src
SUSE Linux Enterprise Software Development Kit 12.2 s390x
-
Packageslibopenssl-devel
Include Files and Libraries mandatory for Developmentopenssl1.0.2j-59.1 lock rpm
Secure Sockets and Transport Layer Security1.0.2j-59.1 lock src
SUSE Linux Enterprise Software Development Kit 12.2 x86_64
-
Packageslibopenssl-devel
Include Files and Libraries mandatory for Developmentopenssl1.0.2j-59.1 lock rpm
Secure Sockets and Transport Layer Security1.0.2j-59.1 lock src