This update for libopenssl0_9_8 fixes the following issues:
- CVE-2016-0800 aka the "DROWN" attack (bsc#968046): OpenSSL was
vulnerable to a cross-protocol attack that could lead to decryption of
TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites
as a Bleichenbacher RSA padding oracle.
This update changes the openssl library to:
* Disable SSLv2 protocol support by default.
This can be overridden by setting the environment variable
"OPENSSL_ALLOW_SSL2" or by using SSL_CTX_clear_options using the
SSL_OP_NO_SSLv2 flag.
Note that various services and clients had already disabled SSL
protocol 2 by default previously.
* Disable all weak EXPORT ciphers by default. These can be reenabled if
required by old legacy software using the environment variable
"OPENSSL_ALLOW_EXPORT".
- CVE-2016-0797 (bnc#968048): The BN_hex2bn() and BN_dec2bn() functions
had a bug that could result in an...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.1:
zypper in -t patch openSUSE-2016-294=1
- openSUSE 13.2:
zypper in -t patch openSUSE-2016-294=1
To bring your system up-to-date, use "zypper patch".
- openSUSE Leap 42.1 (i586 x86_64):
libopenssl0_9_8-0.9.8zh-14.1
libopenssl0_9_8-debuginfo-0.9.8zh-14.1
libopenssl0_9_8-debugsource-0.9.8zh-14.1
- openSUSE Leap 42.1 (x86_64):
libopenssl0_9_8-32bit-0.9.8zh-14.1
libopenssl0_9_8-debuginfo-32bit-0.9.8zh-14.1
- openSUSE 13.2 (i586 x86_64):
libopenssl0_9_8-0.9.8zh-9.3.1
libopenssl0_9_8-debuginfo-0.9.8zh-9.3.1
libopenssl0_9_8-debugsource-0.9.8zh-9.3.1
- openSUSE 13.2 (x86_64):
libopenssl0_9_8-32bit-0.9.8zh-9.3.1
libopenssl0_9_8-debuginfo-32bit-0.9.8zh-9.3.1
https://www.suse.com/security/cve/CVE-2013-0166.html
https://www.suse.com/security/cve/CVE-2013-0169.html
https://www.suse.com/security/cve/CVE-2014-0076.html
https://www.suse.com/security/cve/CVE-2014-0195.html
https://www.suse.com/security/cve/CVE-2014-0221.html
https://www.suse.com/security/cve/CVE-2014-0224.html
https://www.suse.com/security/cve/CVE-2014-3470.html
https://www.suse.com/security/cve/CVE-2014-3505.html
https://www.suse.com/security/cve/CVE-2014-3506.html
https://www.suse.com/security/cve/CVE-2014-3507.html
https://www.suse.com/security/cve/CVE-2014-3508.html
https://www.suse.com/security/cve/CVE-2014-3510.html
https://www.suse.com/security/cve/CVE-2014-3566.html
https://www.suse.com/security/cve/CVE-2014-3567.html
https://www.suse.com/security/cve/CVE-2014-3568.html
https://www.suse.com/security/cve/CVE-2014-3569.html
https://www.suse.com/security/cve/CVE-2014-3570.html
https://www.suse.com/security/cve/CVE-2014-3571.html
https://www.suse.com/security/cve/CVE-2014-3572.html
https://www....
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.