Oval Definition:oval:org.opensuse.security:def:20188970
Revision Date:2022-06-30Version:1
Title:CVE-2018-8970
Description:

The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-8970
Mitre CVE-2018-8970
SUSE CVE-2018-8970
openSUSE-SU-2018:2597-1
Platform(s):openSUSE Leap 42.3
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Leap 42.3 is installed
  • AND Package Information
  • libcrypto43-2.8.0-11 is installed
  • AND libcrypto43 is signed with openSUSE key
  • OR
  • libcrypto43-32bit-2.8.0-11 is installed
  • AND libcrypto43-32bit is signed with openSUSE key
  • OR
  • libressl-2.8.0-11 is installed
  • AND libressl is signed with openSUSE key
  • OR
  • libressl-devel-2.8.0-11 is installed
  • AND libressl-devel is signed with openSUSE key
  • OR
  • libressl-devel-32bit-2.8.0-11 is installed
  • AND libressl-devel-32bit is signed with openSUSE key
  • OR
  • libressl-devel-doc-2.8.0-11 is installed
  • AND libressl-devel-doc is signed with openSUSE key
  • OR
  • libssl45-2.8.0-11 is installed
  • AND libssl45 is signed with openSUSE key
  • OR
  • libssl45-32bit-2.8.0-11 is installed
  • AND libssl45-32bit is signed with openSUSE key
  • OR
  • libtls17-2.8.0-11 is installed
  • AND libtls17 is signed with openSUSE key
  • OR
  • libtls17-32bit-2.8.0-11 is installed
  • AND libtls17-32bit is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • libcrypto46-3.3.4-1.2 is installed
  • OR libcrypto46-32bit-3.3.4-1.2 is installed
  • OR libressl-3.3.4-1.2 is installed
  • OR libressl-devel-3.3.4-1.2 is installed
  • OR libressl-devel-32bit-3.3.4-1.2 is installed
  • OR libressl-devel-doc-3.3.4-1.2 is installed
  • OR libssl48-3.3.4-1.2 is installed
  • OR libssl48-32bit-3.3.4-1.2 is installed
  • OR libtls20-3.3.4-1.2 is installed
  • OR libtls20-32bit-3.3.4-1.2 is installed
  • BACK