Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for openssl fixes various security issues:
Security issues fixed:
- CVE-2016-0800 aka the "DROWN" attack (bsc#968046): OpenSSL was
vulnerable to a cross-protocol attack that could lead to decryption of
TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites
as a Bleichenbacher RSA padding oracle.
This update changes the openssl library to:
* Disable SSLv2 protocol support by default.
This can be overridden by setting the environment variable
"OPENSSL_ALLOW_SSL2" or by using SSL_CTX_clear_options using the
SSL_OP_NO_SSLv2 flag.
Note that various services and clients had already disabled SSL
protocol 2 by default previously.
* Disable all weak EXPORT ciphers by default. These can be reenabled if
required by old legacy software using the environment variable
"OPENSSL_ALLOW_EXPORT".
- CVE-2016-0702 aka the "CacheBleed" attack. (bsc#968050) Various changes
in the...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 13.1:
zypper in -t patch 2016-292=1
To bring your system up-to-date, use "zypper patch".
- openSUSE 13.1 (i586 x86_64):
libopenssl-devel-1.0.1k-11.84.1
libopenssl1_0_0-1.0.1k-11.84.1
libopenssl1_0_0-debuginfo-1.0.1k-11.84.1
openssl-1.0.1k-11.84.1
openssl-debuginfo-1.0.1k-11.84.1
openssl-debugsource-1.0.1k-11.84.1
- openSUSE 13.1 (x86_64):
libopenssl-devel-32bit-1.0.1k-11.84.1
libopenssl1_0_0-32bit-1.0.1k-11.84.1
libopenssl1_0_0-debuginfo-32bit-1.0.1k-11.84.1
- openSUSE 13.1 (noarch):
openssl-doc-1.0.1k-11.84.1
Get the latest Linux and open source security news straight to your inbox.