Oval Definition:oval:org.opensuse.security:def:55479
Revision Date:2020-12-01Version:1
Title:Security update for openssl (Important)
Description:



OpenSSL was updated to fix various security issues.

Following security issues were fixed: - CVE-2015-0209: A Use After Free following d2i_ECPrivatekey error was fixed which could lead to crashes for attacker supplied Elliptic Curve keys. This could be exploited over SSL connections with client supplied keys.

- CVE-2015-0286: A segmentation fault in ASN1_TYPE_cmp was fixed that could be exploited by attackers when e.g. client authentication is used. This could be exploited over SSL connections.

- CVE-2015-0287: A ASN.1 structure reuse memory corruption was fixed. This problem can not be exploited over regular SSL connections, only if specific client programs use specific ASN.1 routines.

- CVE-2015-0288: A X509_to_X509_REQ NULL pointer dereference was fixed, which could lead to crashes. This function is not commonly used, and not reachable over SSL methods.

- CVE-2015-0289: Several PKCS7 NULL pointer dereferences were fixed, which could lead to crashes of programs using the PKCS7 APIs. The SSL apis do not use those by default.

- CVE-2015-0293: Denial of service via reachable assert in SSLv2 servers, could be used by remote attackers to terminate the server process. Note that this requires SSLv2 being allowed, which is not the default.
Family:unixClass:patch
Status:Reference(s):1004237
1038564
1042892
1044878
1045986
1050751
1065237
1085790
1090671
1099257
1113094
1113672
1119183
1120374
1121816
1121821
1122983
1131709
1132045
1139083
702028
762735
854817
854824
858727
866911
867362
895814
899303
903279
905245
905246
905247
905248
907092
908491
915183
917630
918618
919648
920236
921430
922488
922496
922499
922500
924071
924526
926369
926953
927455
927697
927786
928131
929475
929696
929879
929974
930092
930399
930579
930599
930972
931124
931403
931538
931620
931860
931988
932348
932793
932897
932898
932899
932900
932967
933117
933429
933637
933896
933904
933907
934160
935083
935085
935088
935174
935542
935881
935918
936012
936423
936445
936446
936502
936556
936831
936875
937032
937087
937609
937612
937613
937616
938022
938023
938024
CVE-2009-0758
CVE-2010-2244
CVE-2011-1002
CVE-2011-2485
CVE-2012-2370
CVE-2012-4406
CVE-2013-4242
CVE-2014-3591
CVE-2014-7960
CVE-2014-8710
CVE-2014-8711
CVE-2014-8712
CVE-2014-8713
CVE-2014-8714
CVE-2014-9728
CVE-2014-9729
CVE-2014-9730
CVE-2014-9731
CVE-2015-0209
CVE-2015-0286
CVE-2015-0287
CVE-2015-0288
CVE-2015-0289
CVE-2015-0293
CVE-2015-0837
CVE-2015-1805
CVE-2015-1856
CVE-2015-3212
CVE-2015-4036
CVE-2015-4167
CVE-2015-4692
CVE-2015-5223
CVE-2015-5364
CVE-2015-5366
CVE-2016-8602
CVE-2017-1000368
CVE-2017-10989
CVE-2017-7533
CVE-2017-8890
CVE-2017-9242
CVE-2018-12900
CVE-2018-18500
CVE-2018-18501
CVE-2018-18505
CVE-2018-18557
CVE-2018-18661
CVE-2018-8740
CVE-2019-12900
CVE-2019-6109
CVE-2019-6111
SUSE-SU-2015:0426-1
SUSE-SU-2015:0541-1
SUSE-SU-2015:1324-1
SUSE-SU-2016:2654-1
SUSE-SU-2017:1778-1
SUSE-SU-2017:2090-1
SUSE-SU-2017:2094-1
SUSE-SU-2018:3911-2
SUSE-SU-2019:0336-1
SUSE-SU-2019:1208-1
SUSE-SU-2019:1524-1
SUSE-SU-2019:2013-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • MozillaFirefox-60.0-lp150.2 is installed
  • OR MozillaFirefox-translations-common-60.0-lp150.2 is installed
  • OR MozillaFirefox-translations-other-60.0-lp150.2 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • gvfs-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-32bit-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-backend-afc-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-backend-samba-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-backends-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-devel-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-fuse-1.34.2.1-lp151.6.3 is installed
  • OR gvfs-lang-1.34.2.1-lp151.6.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • gtk2-2.18.9-0.23 is installed
  • OR gtk2-32bit-2.18.9-0.23 is installed
  • OR gtk2-devel-2.18.9-0.23 is installed
  • OR gtk2-lang-2.18.9-0.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND wireshark-1.10.11-0.2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • libopenssl1_0_0-1.0.1i-20 is installed
  • OR libopenssl1_0_0-32bit-1.0.1i-20 is installed
  • OR openssl-1.0.1i-20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • openssh-7.2p2-74.42 is installed
  • OR openssh-askpass-gnome-7.2p2-74.42 is installed
  • OR openssh-helpers-7.2p2-74.42 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • libtiff5-4.0.9-44.27 is installed
  • OR libtiff5-32bit-4.0.9-44.27 is installed
  • OR tiff-4.0.9-44.27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • avahi-0.6.31-20 is installed
  • OR avahi-lang-0.6.31-20 is installed
  • OR avahi-utils-0.6.31-20 is installed
  • OR libavahi-client3-0.6.31-20 is installed
  • OR libavahi-client3-32bit-0.6.31-20 is installed
  • OR libavahi-common3-0.6.31-20 is installed
  • OR libavahi-common3-32bit-0.6.31-20 is installed
  • OR libavahi-core7-0.6.31-20 is installed
  • OR libdns_sd-0.6.31-20 is installed
  • OR libdns_sd-32bit-0.6.31-20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND sudo-1.8.10p3-2.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND ft2demos-2.6.3-7.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • qemu-2.6.2-41.49 is installed
  • OR qemu-block-curl-2.6.2-41.49 is installed
  • OR qemu-block-rbd-2.6.2-41.49 is installed
  • OR qemu-block-ssh-2.6.2-41.49 is installed
  • OR qemu-guest-agent-2.6.2-41.49 is installed
  • OR qemu-ipxe-1.0.0-41.49 is installed
  • OR qemu-kvm-2.6.2-41.49 is installed
  • OR qemu-lang-2.6.2-41.49 is installed
  • OR qemu-seabios-1.9.1-41.49 is installed
  • OR qemu-sgabios-8-41.49 is installed
  • OR qemu-tools-2.6.2-41.49 is installed
  • OR qemu-vgabios-1.9.1-41.49 is installed
  • OR qemu-x86-2.6.2-41.49 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • java-1_7_0-openjdk-1.7.0.221-43.22 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.221-43.22 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.221-43.22 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.221-43.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_74-92_29-default-11-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_10-11-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • emacs-24.3-19 is installed
  • OR emacs-el-24.3-19 is installed
  • OR emacs-info-24.3-19 is installed
  • OR emacs-nox-24.3-19 is installed
  • OR emacs-x11-24.3-19 is installed
  • OR etags-24.3-19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • tomcat-8.0.53-29.22 is installed
  • OR tomcat-admin-webapps-8.0.53-29.22 is installed
  • OR tomcat-docs-webapp-8.0.53-29.22 is installed
  • OR tomcat-el-3_0-api-8.0.53-29.22 is installed
  • OR tomcat-javadoc-8.0.53-29.22 is installed
  • OR tomcat-jsp-2_3-api-8.0.53-29.22 is installed
  • OR tomcat-lib-8.0.53-29.22 is installed
  • OR tomcat-servlet-3_1-api-8.0.53-29.22 is installed
  • OR tomcat-webapps-8.0.53-29.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_175-94_79-default-6-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_23-6-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libtirpc-1.0.1-17.6 is installed
  • OR libtirpc-netconfig-1.0.1-17.6 is installed
  • OR libtirpc3-1.0.1-17.6 is installed
  • OR libtirpc3-32bit-1.0.1-17.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • lcms2-2.7-9.7 is installed
  • OR liblcms2-2-2.7-9.7 is installed
  • OR liblcms2-2-32bit-2.7-9.7 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND Package Information
  • openstack-swift-2.1.0-4 is installed
  • OR openstack-swift-account-2.1.0-4 is installed
  • OR openstack-swift-container-2.1.0-4 is installed
  • OR openstack-swift-object-2.1.0-4 is installed
  • OR openstack-swift-proxy-2.1.0-4 is installed
  • OR python-swift-2.1.0-4 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • libopenssl-devel-1.0.2j-60.30 is installed
  • OR libopenssl1_0_0-1.0.2j-60.30 is installed
  • OR libopenssl1_0_0-32bit-1.0.2j-60.30 is installed
  • OR libopenssl1_0_0-hmac-1.0.2j-60.30 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.30 is installed
  • OR openssl-1.0.2j-60.30 is installed
  • OR openssl-doc-1.0.2j-60.30 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND binutils-2.32-9.33 is installed
  • BACK