Oval Definition:oval:org.opensuse.security:def:81533
Revision Date:2018-09-28Version:1
Title:Security update for openssl (Moderate)
Description:

This update for openssl fixes the following issues:

These security issues were fixed:

- Prevent One&Done side-channel attack on RSA that allowed physically near attackers to use EM emanations to recover information (bsc#1104789) - CVE-2018-0737: The RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could have recovered the private key (bsc#1089039)

These non-security issues were fixed:

- Add openssl(cli) Provide so the packages that require the openssl binary can require this instead of the new openssl meta package (bsc#1101470) - Fixed path to the engines which are under /lib64 on SLE-12 (bsc#1101246, bsc#997043)
Family:unixClass:patch
Status:Reference(s):1089039
1101246
1101470
1104789
1106197
997043
CVE-2018-0737
SUSE-SU-2018:2928-1
Platform(s):SUSE Linux Enterprise Server 12 SP2-LTSS
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • libopenssl-devel-1.0.2j-60.39.1 is installed
  • OR libopenssl1_0_0-1.0.2j-60.39.1 is installed
  • OR libopenssl1_0_0-32bit-1.0.2j-60.39.1 is installed
  • OR libopenssl1_0_0-hmac-1.0.2j-60.39.1 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.39.1 is installed
  • OR openssl-1.0.2j-60.39.1 is installed
  • OR openssl-doc-1.0.2j-60.39.1 is installed
  • BACK