Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE 13.2 Advisory: 2015:1277-1 Important Libressl DoS Issues

opensuse
Calendar Grey July 22, 2015
Dist Opensuse Esm H88
This crucial patch release resolves 12 vulnerabilities in libressl for openSUSE 15.3, improving overall system security.
An update that solves 16 vulnerabilities and has one errata An update that solves 16 vulnerabilities and has one errata An update that solves 16 vulnerabilities and has one errata ...

Description

libressl was updated to version 2.2.1 to fix 16 security issues.

LibreSSL is a fork of OpenSSL. Because of that CVEs affecting OpenSSL

often also affect LibreSSL.

These security issues were fixed:

- CVE-2014-3570: The BN_sqr implementation in OpenSSL before 0.9.8zd,

1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k did not properly calculate

the square of a BIGNUM value, which might make it easier for remote

attackers to defeat cryptographic protection mechanisms via unspecified

vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c,

and crypto/bn/bn_asm.c (bsc#912296).

- CVE-2014-3572: The ssl3_get_key_exchange function in s3_clnt.c in

OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k

allowed remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks

and trigger a loss of forward secrecy by omitting the ServerKeyExchange

message (bsc#912015).

- CVE-2015-1792: The do_free_upto function...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-507=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

libcrypto34-2.2.1-2.3.1

libcrypto34-debuginfo-2.2.1-2.3.1

libressl-2.2.1-2.3.1

libressl-debuginfo-2.2.1-2.3.1

libressl-debugsource-2.2.1-2.3.1

libressl-devel-2.2.1-2.3.1

libssl33-2.2.1-2.3.1

libssl33-debuginfo-2.2.1-2.3.1

libtls4-2.2.1-2.3.1

libtls4-debuginfo-2.2.1-2.3.1

- openSUSE 13.2 (x86_64):

libcrypto34-32bit-2.2.1-2.3.1

libcrypto34-debuginfo-32bit-2.2.1-2.3.1

libressl-devel-32bit-2.2.1-2.3.1

libssl33-32bit-2.2.1-2.3.1

libssl33-debuginfo-32bit-2.2.1-2.3.1

libtls4-32bit-2.2.1-2.3.1

libtls4-debuginfo-32bit-2.2.1-2.3.1

- openSUSE 13.2 (noarch):

libressl-devel-doc-2.2.1-2.3.1

References

https://www.suse.com/security/cve/CVE-2014-3570.html

https://www.suse.com/security/cve/CVE-2014-3572.html

https://www.suse.com/security/cve/CVE-2014-8176.html

https://www.suse.com/security/cve/CVE-2014-8275.html

https://www.suse.com/security/cve/CVE-2015-0205.html

https://www.suse.com/security/cve/CVE-2015-0206.html

https://www.suse.com/security/cve/CVE-2015-0209.html

https://www.suse.com/security/cve/CVE-2015-0286.html

https://www.suse.com/security/cve/CVE-2015-0287.html

https://www.suse.com/security/cve/CVE-2015-0288.html

https://www.suse.com/security/cve/CVE-2015-0289.html

https://www.suse.com/security/cve/CVE-2015-1788.html

https://www.suse.com/security/cve/CVE-2015-1789.html

https://www.suse.com/security/cve/CVE-2015-1790.html

https://www.suse.com/security/cve/CVE-2015-1792.html

https://www.suse.com/security/cve/CVE-2015-4000.html

https://bugzilla.suse.com/show_bug.cgi?id=912015

https://bugzilla.suse.com/show_bug.cgi?id=912018

https://bugzilla.suse.com/show_bug.cgi?id=912292

https://bugzilla.suse.co...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1277-1
Rating: important
Affected Products: openSUSE 13.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here