Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE 42.1, 13.2: 2016:0640-1 Important: libopenssl Security Issue

opensuse
Calendar Grey March 3, 2016
Dist Opensuse Esm H88
Critical openSUSE Security Patch addresses 45 flaws in libopenssl1_0_2 to improve overall security and performance.
An update that fixes 37 vulnerabilities is now available

Description

This update for libopenssl0_9_8 fixes the following issues:

- CVE-2016-0800 aka the "DROWN" attack (bsc#968046): OpenSSL was

vulnerable to a cross-protocol attack that could lead to decryption of

TLS sessions by using a server supporting SSLv2 and EXPORT cipher suites

as a Bleichenbacher RSA padding oracle.

This update changes the openssl library to:

* Disable SSLv2 protocol support by default.

This can be overridden by setting the environment variable

"OPENSSL_ALLOW_SSL2" or by using SSL_CTX_clear_options using the

SSL_OP_NO_SSLv2 flag.

Note that various services and clients had already disabled SSL

protocol 2 by default previously.

* Disable all weak EXPORT ciphers by default. These can be reenabled if

required by old legacy software using the environment variable

"OPENSSL_ALLOW_EXPORT".

- CVE-2016-0797 (bnc#968048): The BN_hex2bn() and BN_dec2bn() functions

had a bug that could result in an...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-294=1

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-294=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

libopenssl0_9_8-0.9.8zh-14.1

libopenssl0_9_8-debuginfo-0.9.8zh-14.1

libopenssl0_9_8-debugsource-0.9.8zh-14.1

- openSUSE Leap 42.1 (x86_64):

libopenssl0_9_8-32bit-0.9.8zh-14.1

libopenssl0_9_8-debuginfo-32bit-0.9.8zh-14.1

- openSUSE 13.2 (i586 x86_64):

libopenssl0_9_8-0.9.8zh-9.3.1

libopenssl0_9_8-debuginfo-0.9.8zh-9.3.1

libopenssl0_9_8-debugsource-0.9.8zh-9.3.1

- openSUSE 13.2 (x86_64):

libopenssl0_9_8-32bit-0.9.8zh-9.3.1

libopenssl0_9_8-debuginfo-32bit-0.9.8zh-9.3.1

References

https://www.suse.com/security/cve/CVE-2013-0166.html

https://www.suse.com/security/cve/CVE-2013-0169.html

https://www.suse.com/security/cve/CVE-2014-0076.html

https://www.suse.com/security/cve/CVE-2014-0195.html

https://www.suse.com/security/cve/CVE-2014-0221.html

https://www.suse.com/security/cve/CVE-2014-0224.html

https://www.suse.com/security/cve/CVE-2014-3470.html

https://www.suse.com/security/cve/CVE-2014-3505.html

https://www.suse.com/security/cve/CVE-2014-3506.html

https://www.suse.com/security/cve/CVE-2014-3507.html

https://www.suse.com/security/cve/CVE-2014-3508.html

https://www.suse.com/security/cve/CVE-2014-3510.html

https://www.suse.com/security/cve/CVE-2014-3566.html

https://www.suse.com/security/cve/CVE-2014-3567.html

https://www.suse.com/security/cve/CVE-2014-3568.html

https://www.suse.com/security/cve/CVE-2014-3569.html

https://www.suse.com/security/cve/CVE-2014-3570.html

https://www.suse.com/security/cve/CVE-2014-3571.html

https://www.suse.com/security/cve/CVE-2014-3572.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:0640-1
Rating: important
Affected Products: openSUSE Leap 42.1 openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here