Revision Date: | 2020-12-01 | Version: | 1 |
Title: | Security update for openssl (Important) |
Description: |
This update for openssl fixes the following issues:
- OpenSSL Security Advisory [07 Dec 2017] * CVE-2017-3737: OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an \'error state\' mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and would immediately fail if you attempted to continue the handshake. This works as designed for the explicit handshake functions (SSL_do_handshake(), SSL_accept() and SSL_connect()), however due to a bug it does not work correctly if SSL_read() or SSL_write() is called directly. In that scenario, if the handshake fails then a fatal error will be returned in the initial function call. If SSL_read()/SSL_write() is subsequently called by the application for the same SSL object then it will succeed and the data is passed without being decrypted/encrypted directly from the SSL/TLS record layer. In order to exploit this issue an application bug would have to be present that resulted in a call to SSL_read()/SSL_write() being issued after having already received a fatal error. OpenSSL version 1.0.2b-1.0.2m are affected. Fixed in OpenSSL 1.0.2n. OpenSSL 1.1.0 is not affected. (bsc#1071905) * CVE-2017-3738: There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. (bsc#1071906)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1007728 1012260 1021577 1026191 1038505 1038690 1039357 1041469 1041894 1049703 1061204 1064786 1065464 1066489 1071905 1071906 1073210 1078436 1091551 1092697 1094767 1096515 1099497 1104668 1107343 1108771 1108986 1109363 1109465 1110506 1110507 1112852 1118319 1118320 1137597 1140747 1159913 1165631 703591 839074 857131 893359 923241 986858 990189 990190 990191 CVE-2006-0855 CVE-2007-1669 CVE-2009-0368 CVE-2010-4523 CVE-2014-2653 CVE-2015-2059 CVE-2015-4410 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2015-8325 CVE-2015-8948 CVE-2016-0705 CVE-2016-0777 CVE-2016-0778 CVE-2016-1908 CVE-2016-3115 CVE-2016-5180 CVE-2016-6210 CVE-2016-6261 CVE-2016-6262 CVE-2016-6263 CVE-2016-6515 CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843 CVE-2017-1000366 CVE-2017-1289 CVE-2017-16541 CVE-2017-3509 CVE-2017-3511 CVE-2017-3533 CVE-2017-3539 CVE-2017-3544 CVE-2017-3732 CVE-2017-3736 CVE-2017-3737 CVE-2017-3738 CVE-2018-10860 CVE-2018-12376 CVE-2018-12377 CVE-2018-12378 CVE-2018-12379 CVE-2018-12381 CVE-2018-12383 CVE-2018-12385 CVE-2018-12386 CVE-2018-12387 CVE-2018-12389 CVE-2018-12390 CVE-2018-12392 CVE-2018-12393 CVE-2018-12395 CVE-2018-12396 CVE-2018-12397 CVE-2018-12539 CVE-2018-1517 CVE-2018-1656 CVE-2018-2940 CVE-2018-2952 CVE-2018-2964 CVE-2018-2973 CVE-2018-9568 CVE-2019-11477 CVE-2019-11478 CVE-2019-5108 CVE-2020-1749 SUSE-SU-2016:2079-1 SUSE-SU-2016:3286-1 SUSE-SU-2017:1385-1 SUSE-SU-2017:1614-1 SUSE-SU-2017:3343-1 SUSE-SU-2018:2385-1 SUSE-SU-2018:2839-1 SUSE-SU-2018:3591-1 SUSE-SU-2018:3749-1 SUSE-SU-2019:1924-1 SUSE-SU-2020:0868-1
|
Platform(s): | openSUSE Leap 15.0 openSUSE Leap 15.1 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP1-LTSS SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP2-BCL SUSE Linux Enterprise Server 12 SP2-ESPOS SUSE Linux Enterprise Server 12 SP2-LTSS SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP3-LTSS SUSE Linux Enterprise Server 12 SP3-TERADATA SUSE Linux Enterprise Server 12 SP4 SUSE OpenStack Cloud 6 SUSE OpenStack Cloud 7 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.0 is installed AND Package Information
gstreamer-plugins-good-1.12.5-lp150.1 is installed
OR gstreamer-plugins-good-lang-1.12.5-lp150.1 is installed
|
Definition Synopsis |
openSUSE Leap 15.1 is installed
AND Package Information
libopenssl-1_0_0-devel-1.0.2p-lp151.5.3 is installed
OR libopenssl-1_0_0-devel-32bit-1.0.2p-lp151.5.3 is installed
OR libopenssl1_0_0-1.0.2p-lp151.5.3 is installed
OR libopenssl1_0_0-32bit-1.0.2p-lp151.5.3 is installed
OR libopenssl1_0_0-hmac-1.0.2p-lp151.5.3 is installed
OR libopenssl1_0_0-hmac-32bit-1.0.2p-lp151.5.3 is installed
OR openssl-1_0_0-1.0.2p-lp151.5.3 is installed
OR openssl-1_0_0-cavs-1.0.2p-lp151.5.3 is installed
OR openssl-1_0_0-doc-1.0.2p-lp151.5.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed
AND Package Information
libopenssl-devel-1.0.2j-60.20 is installed
OR libopenssl1_0_0-1.0.2j-60.20 is installed
OR libopenssl1_0_0-32bit-1.0.2j-60.20 is installed
OR openssl-1.0.2j-60.20 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1 is installed
AND opensc-0.13.0-1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1-LTSS is installed
AND Package Information
kgraft-patch-3_12_74-60_64_96-default-7-2 is installed
OR kgraft-patch-3_12_74-60_64_96-xen-7-2 is installed
OR kgraft-patch-SLE12-SP1_Update_29-7-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2 is installed
AND Package Information
openssh-7.2p2-55 is installed
OR openssh-fips-7.2p2-55 is installed
OR openssh-helpers-7.2p2-55 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-BCL is installed
AND Package Information
libopenssl-devel-1.0.2j-60.30 is installed
OR libopenssl1_0_0-1.0.2j-60.30 is installed
OR libopenssl1_0_0-32bit-1.0.2j-60.30 is installed
OR libopenssl1_0_0-hmac-1.0.2j-60.30 is installed
OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.30 is installed
OR openssl-1.0.2j-60.30 is installed
OR openssl-doc-1.0.2j-60.30 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
AND Package Information
xen-4.7.6_04-43.39 is installed
OR xen-doc-html-4.7.6_04-43.39 is installed
OR xen-libs-4.7.6_04-43.39 is installed
OR xen-libs-32bit-4.7.6_04-43.39 is installed
OR xen-tools-4.7.6_04-43.39 is installed
OR xen-tools-domU-4.7.6_04-43.39 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2-LTSS is installed
AND Package Information
kgraft-patch-4_4_74-92_29-default-12-2 is installed
OR kgraft-patch-SLE12-SP2_Update_10-12-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
eog-3.20.4-7 is installed
OR eog-lang-3.20.4-7 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-LTSS is installed
AND Package Information
MozillaFirefox-68.3.0-109.98 is installed
OR MozillaFirefox-translations-common-68.3.0-109.98 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
AND Package Information
libpython2_7-1_0-2.7.17-28.42 is installed
OR libpython2_7-1_0-32bit-2.7.17-28.42 is installed
OR python-2.7.17-28.42 is installed
OR python-32bit-2.7.17-28.42 is installed
OR python-base-2.7.17-28.42 is installed
OR python-base-32bit-2.7.17-28.42 is installed
OR python-curses-2.7.17-28.42 is installed
OR python-demo-2.7.17-28.42 is installed
OR python-devel-2.7.17-28.42 is installed
OR python-doc-2.7.17-28.42 is installed
OR python-doc-pdf-2.7.17-28.42 is installed
OR python-gdbm-2.7.17-28.42 is installed
OR python-idle-2.7.17-28.42 is installed
OR python-rpm-macros-20200207.5feb6c1-3.19 is installed
OR python-tk-2.7.17-28.42 is installed
OR python-xml-2.7.17-28.42 is installed
OR shared-python-startup-0.1-1.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP4 is installed
AND Package Information
expat-2.1.0-21.3 is installed
OR libexpat1-2.1.0-21.3 is installed
OR libexpat1-32bit-2.1.0-21.3 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 6 is installed
AND ruby2.1-rubygem-bson-1_11-1.11.1-2 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 7 is installed
AND Package Information
java-1_8_0-ibm-1.8.0_sr5.20-30.36 is installed
OR java-1_8_0-ibm-alsa-1.8.0_sr5.20-30.36 is installed
OR java-1_8_0-ibm-devel-1.8.0_sr5.20-30.36 is installed
OR java-1_8_0-ibm-plugin-1.8.0_sr5.20-30.36 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 8 is installed
AND mutt-1.10.1-55.11 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 8 is installed
AND ipmitool-1.8.18-5.9 is installed
|