Oval Definition:oval:org.opensuse.security:def:64676
Revision Date:2021-03-25Version:1
Title:Security update for openssl-1_1 (Important)
Description:

This update for openssl-1_1 fixes the security issue:

CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension but includes a signature_algorithms_cert extension, then a NULL pointer dereference will result, leading to a crash and a denial of service attack. OpenSSL TLS clients are not impacted by this issue. [bsc#1183852]
Family:unixClass:patch
Status:Reference(s):1163102
1163103
1163104
1166916
1171186
1172442
1172443
1173157
1174139
1174157
1174230
1174955
1175465
1176384
1176430
1176756
1176899
1177155
1177977
1183852
CVE-2014-0240
CVE-2015-5174
CVE-2015-5345
CVE-2015-5346
CVE-2015-5351
CVE-2016-0706
CVE-2016-0714
CVE-2016-0763
CVE-2016-3092
CVE-2016-8745
CVE-2017-12617
CVE-2017-5647
CVE-2017-5648
CVE-2017-5664
CVE-2018-11784
CVE-2018-1336
CVE-2018-8014
CVE-2018-8034
CVE-2018-8037
CVE-2019-15604
CVE-2019-15605
CVE-2019-15606
CVE-2020-11080
CVE-2020-12387
CVE-2020-12392
CVE-2020-12393
CVE-2020-12395
CVE-2020-12397
CVE-2020-14556
CVE-2020-14562
CVE-2020-14573
CVE-2020-14577
CVE-2020-14581
CVE-2020-14583
CVE-2020-14593
CVE-2020-14621
CVE-2020-15673
CVE-2020-15676
CVE-2020-15677
CVE-2020-15678
CVE-2020-15683
CVE-2020-15708
CVE-2020-15969
CVE-2020-25637
CVE-2020-6831
CVE-2020-7598
CVE-2020-8174
CVE-2021-3449
openSUSE-SU-2020:0293-1
openSUSE-SU-2020:0643-1
openSUSE-SU-2020:0802-1
openSUSE-SU-2020:1191-1
openSUSE-SU-2020:1777-1
openSUSE-SU-2020:1780-1
SUSE-SU-2021:0955-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Public Cloud 15 SP1
SUSE Linux Enterprise Module for Web Scripting 15 SP1
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Server 4.1
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • nodejs8-8.17.0-lp151.2.12 is installed
  • OR nodejs8-devel-8.17.0-lp151.2.12 is installed
  • OR nodejs8-docs-8.17.0-lp151.2.12 is installed
  • OR npm8-8.17.0-lp151.2.12 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • java-11-openjdk-11.0.8.0-lp152.2.3 is installed
  • OR java-11-openjdk-accessibility-11.0.8.0-lp152.2.3 is installed
  • OR java-11-openjdk-demo-11.0.8.0-lp152.2.3 is installed
  • OR java-11-openjdk-devel-11.0.8.0-lp152.2.3 is installed
  • OR java-11-openjdk-headless-11.0.8.0-lp152.2.3 is installed
  • OR java-11-openjdk-javadoc-11.0.8.0-lp152.2.3 is installed
  • OR java-11-openjdk-jmods-11.0.8.0-lp152.2.3 is installed
  • OR java-11-openjdk-src-11.0.8.0-lp152.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • libopenssl-1_1-devel-1.1.1d-11.20.1 is installed
  • OR libopenssl1_1-1.1.1d-11.20.1 is installed
  • OR libopenssl1_1-32bit-1.1.1d-11.20.1 is installed
  • OR libopenssl1_1-hmac-1.1.1d-11.20.1 is installed
  • OR libopenssl1_1-hmac-32bit-1.1.1d-11.20.1 is installed
  • OR openssl-1_1-1.1.1d-11.20.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Public Cloud 15 SP1 is installed
  • AND apache2-mod_wsgi-4.5.18-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Web Scripting 15 SP1 is installed
  • AND Package Information
  • tomcat-9.0.14-2 is installed
  • OR tomcat-admin-webapps-9.0.14-2 is installed
  • OR tomcat-el-3_0-api-9.0.14-2 is installed
  • OR tomcat-jsp-2_3-api-9.0.14-2 is installed
  • OR tomcat-lib-9.0.14-2 is installed
  • OR tomcat-servlet-4_0-api-9.0.14-2 is installed
  • OR tomcat-webapps-9.0.14-2 is installed
  • BACK