Oval Definition:oval:org.opensuse.security:def:56587
Revision Date:2020-12-01Version:1
Title:Security update for compat-openssl098 (Moderate)
Description:

This update for compat-openssl098 fixes the following security issues:

- CVE-2018-0732: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server could have sent a very large prime value to the client. This caused the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack (bsc#1097158) - Blinding enhancements for ECDSA and DSA (bsc#1097624, bsc#1098592) - CVE-2018-0737: The RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could have recovered the private key (bsc#1089039) - CVE-2018-0739: Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could have resulted in DoS (bsc#1087102).
Family:unixClass:patch
Status:Reference(s):1002998
1014524
1015567
1022098
1023988
1029912
1040543
1041447
1041470
1045986
1050896
1052829
1060644
1061310
1069591
1087102
1089039
1090174
1097108
1097158
1097624
1098592
1100453
1101506
1101644
1101645
1101651
1101656
1106923
1108835
1109252
1110445
1111278
1112024
1112142
1112143
1112144
1112146
1112147
1112152
1112153
1113083
1113632
1113665
1114828
1116600
1133375
1140868
960674
996004
CVE-2009-5044
CVE-2009-5080
CVE-2009-5081
CVE-2013-1430
CVE-2015-3294
CVE-2015-8710
CVE-2016-7103
CVE-2016-7945
CVE-2016-7946
CVE-2017-1000368
CVE-2017-14970
CVE-2017-16927
CVE-2017-6967
CVE-2017-7753
CVE-2017-7779
CVE-2017-7782
CVE-2017-7784
CVE-2017-7785
CVE-2017-7786
CVE-2017-7787
CVE-2017-7791
CVE-2017-7792
CVE-2017-7798
CVE-2017-7800
CVE-2017-7801
CVE-2017-7802
CVE-2017-7803
CVE-2017-7804
CVE-2017-7807
CVE-2017-9214
CVE-2017-9263
CVE-2017-9265
CVE-2018-0732
CVE-2018-0737
CVE-2018-0739
CVE-2018-10853
CVE-2018-13785
CVE-2018-15686
CVE-2018-15688
CVE-2018-16435
CVE-2018-16471
CVE-2018-2938
CVE-2018-2940
CVE-2018-2952
CVE-2018-2973
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3214
CVE-2018-3639
CVE-2019-11709
CVE-2019-11711
CVE-2019-11712
CVE-2019-11713
CVE-2019-11715
CVE-2019-11717
CVE-2019-11719
CVE-2019-11729
CVE-2019-11730
CVE-2019-9811
CVE-2019-9928
SUSE-SU-2016:0178-1
SUSE-SU-2016:3047-1
SUSE-SU-2017:1778-1
SUSE-SU-2017:2351-1
SUSE-SU-2017:2589-1
SUSE-SU-2018:0505-1
SUSE-SU-2018:2683-1
SUSE-SU-2018:2684-1
SUSE-SU-2018:3767-1
SUSE-SU-2019:0049-1
SUSE-SU-2019:1440-1
SUSE-SU-2019:1509-1
SUSE-SU-2019:1860-1
SUSE-SU-2019:1861-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND bubblewrap-0.2.0-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND bubblewrap-0.3.3-lp151.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • compat-openssl098-0.9.8j-106.6 is installed
  • OR libopenssl0_9_8-0.9.8j-106.6 is installed
  • OR libopenssl0_9_8-32bit-0.9.8j-106.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • libxml2-2.9.1-17 is installed
  • OR libxml2-2-2.9.1-17 is installed
  • OR libxml2-2-32bit-2.9.1-17 is installed
  • OR libxml2-doc-2.9.1-17 is installed
  • OR libxml2-tools-2.9.1-17 is installed
  • OR python-libxml2-2.9.1-17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND sudo-1.8.10p3-2.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • groff-1.22.2-5 is installed
  • OR groff-full-1.22.2-5 is installed
  • OR gxditview-1.22.2-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.30-38.26 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.30-38.26 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr4.30-38.26 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.30-38.26 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.30-38.26 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND ucode-intel-20180425-13.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_74-92_32-default-10-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_11-10-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND apache2-mod_jk-1.2.40-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND clamav-0.100.3-33.26 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libssh2-1-1.4.3-20.14 is installed
  • OR libssh2-1-32bit-1.4.3-20.14 is installed
  • OR libssh2_org-1.4.3-20.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • ceph-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR ceph-common-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR libcephfs2-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR librados2-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR libradosstriper1-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR librbd1-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR librgw2-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR python-cephfs-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR python-rados-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR python-rbd-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • OR python-rgw-12.2.12+git.1585658687.363df3a813-2.42 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • cracklib-2.9.0-7 is installed
  • OR libcrack2-2.9.0-7 is installed
  • OR libcrack2-32bit-2.9.0-7 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND dnsmasq-utils-2.71-8 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND python-XStatic-jquery-ui-1.11.0.1-2.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libssh2-1-1.4.3-20.9 is installed
  • OR libssh2-1-32bit-1.4.3-20.9 is installed
  • OR libssh2_org-1.4.3-20.9 is installed
  • BACK