Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

openSUSE 13.2: 2016:2391-1 Important: OpenSSL Memory Risk Fix

opensuse
Calendar Grey September 27, 2016
Dist Opensuse Esm H88
Fedora has released an important patch for libxml2 tackling 9 vulnerabilities; serious buffer overflows and denial of service risks highlighted.
An update that solves 11 vulnerabilities and has 5 fixes is An update that solves 11 vulnerabilities and has 5 fixes is An update that solves 11 vulnerabilities and has 5 fixes is ...

Description

This update for openssl fixes the following issues:

OpenSSL Security Advisory [22 Sep 2016] (boo#999665)

Severity: High

* OCSP Status Request extension unbounded memory growth (CVE-2016-6304)

(boo#999666)

Severity: Low

* Pointer arithmetic undefined behaviour (CVE-2016-2177) (boo#982575)

* Constant time flag not preserved in DSA signing (CVE-2016-2178)

(boo#983249)

* DTLS buffered message DoS (CVE-2016-2179) (boo#994844)

* OOB read in TS_OBJ_print_bio() (CVE-2016-2180) (boo#990419)

* DTLS replay protection DoS (CVE-2016-2181) (boo#994749)

* OOB write in BN_bn2dec() (CVE-2016-2182) (boo#993819)

* Birthday attack against 64-bit block ciphers (SWEET32) (CVE-2016-2183)

(boo#995359)

* Malformed SHA512 ticket DoS (CVE-2016-6302) (boo#995324)

* OOB write in MDC2_Update() (CVE-2016-6303) (boo#995377)

* Certificate message OOB reads (CVE-2016-6306) (boo#999668)

More information can be found on

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2016-1130=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

libopenssl-devel-1.0.1k-2.39.1

libopenssl1_0_0-1.0.1k-2.39.1

libopenssl1_0_0-debuginfo-1.0.1k-2.39.1

libopenssl1_0_0-hmac-1.0.1k-2.39.1

openssl-1.0.1k-2.39.1

openssl-debuginfo-1.0.1k-2.39.1

openssl-debugsource-1.0.1k-2.39.1

- openSUSE 13.2 (x86_64):

libopenssl-devel-32bit-1.0.1k-2.39.1

libopenssl1_0_0-32bit-1.0.1k-2.39.1

libopenssl1_0_0-debuginfo-32bit-1.0.1k-2.39.1

libopenssl1_0_0-hmac-32bit-1.0.1k-2.39.1

- openSUSE 13.2 (noarch):

openssl-doc-1.0.1k-2.39.1

References

https://www.suse.com/security/cve/CVE-2016-2177.html

https://www.suse.com/security/cve/CVE-2016-2178.html

https://www.suse.com/security/cve/CVE-2016-2179.html

https://www.suse.com/security/cve/CVE-2016-2180.html

https://www.suse.com/security/cve/CVE-2016-2181.html

https://www.suse.com/security/cve/CVE-2016-2182.html

https://www.suse.com/security/cve/CVE-2016-2183.html

https://www.suse.com/security/cve/CVE-2016-6302.html

https://www.suse.com/security/cve/CVE-2016-6303.html

https://www.suse.com/security/cve/CVE-2016-6304.html

https://www.suse.com/security/cve/CVE-2016-6306.html

https://bugzilla.suse.com/979475

https://bugzilla.suse.com/982575

https://bugzilla.suse.com/983249

https://bugzilla.suse.com/988591

https://bugzilla.suse.com/990419

https://bugzilla.suse.com/993819

https://bugzilla.suse.com/994749

https://bugzilla.suse.com/994844

https://bugzilla.suse.com/995075

https://bugzilla.suse.com/995324

https://bugzilla.suse.com/995359

https://bugzilla.suse.com/995377

https://bugzilla.suse.com/998190

https://bugz...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2391-1
Rating: important
Affected Products: openSUSE 13.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here