Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

openSUSE 42.3 Security Update: 2017:3345-1 Important OpenSSL Fix

opensuse
Calendar Grey December 16, 2017
Dist Opensuse Esm H88
Urgent openssl patch released for openSUSE Leap to tackle various vulnerabilities in versions 42.2 and 42.3.
An update that fixes two vulnerabilities is now available.

Description

This update for openssl fixes the following issues:

- OpenSSL Security Advisory [07 Dec 2017]

* CVE-2017-3737: OpenSSL 1.0.2 (starting from version 1.0.2b) introduced

an \"error state\" mechanism. The intent was that if a fatal error

occurred during a handshake then OpenSSL would move into the error

state and would immediately fail if you attempted to continue the

handshake. This works as designed for the explicit handshake functions

(SSL_do_handshake(), SSL_accept() and SSL_connect()), however due to a

bug it does not work correctly if SSL_read() or SSL_write() is called

directly. In that scenario, if the handshake fails then a fatal error

will be returned in the initial function call. If

SSL_read()/SSL_write() is subsequently called by the application for

the same SSL object then it will succeed and the data is passed

without being decrypted/encrypted directly from the SSL/TLS record

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2017-1381=1

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2017-1381=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (i586 x86_64):

libopenssl-devel-1.0.2j-16.1

libopenssl1_0_0-1.0.2j-16.1

libopenssl1_0_0-debuginfo-1.0.2j-16.1

libopenssl1_0_0-hmac-1.0.2j-16.1

openssl-1.0.2j-16.1

openssl-cavs-1.0.2j-16.1

openssl-cavs-debuginfo-1.0.2j-16.1

openssl-debuginfo-1.0.2j-16.1

openssl-debugsource-1.0.2j-16.1

- openSUSE Leap 42.3 (noarch):

openssl-doc-1.0.2j-16.1

- openSUSE Leap 42.3 (x86_64):

libopenssl-devel-32bit-1.0.2j-16.1

libopenssl1_0_0-32bit-1.0.2j-16.1

libopenssl1_0_0-debuginfo-32bit-1.0.2j-16.1

libopenssl1_0_0-hmac-32bit-1.0.2j-16.1

- openSUSE Leap 42.2 (i586 x86_64):

libopenssl-devel-1.0.2j-6.9.1

libopenssl1_0_0-1.0.2j-6.9.1

libopenssl1_0_0-debuginfo-1.0.2j-6.9.1

libopenssl1_0_0-hmac-1.0.2j-6.9.1

openssl-1.0.2j-6.9.1

openssl-cavs-1.0.2j-6.9.1

openssl-cavs-debuginfo-1.0.2j-6.9.1

openssl-debuginfo-1.0.2j-6.9.1

openssl-debugsource-1.0.2j-6.9.1

- openSUSE Leap 42.2 (x86_64):

libopenssl-devel-32bit-1.0.2j-6.9.1

libopenssl1_0_0-32bit-1.0.2j-6.9.1

libopenssl1_0_0-debuginfo-32bit-1.0.2j-6.9.1

libopenssl1_0_0-hmac-32bi...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-3737.html

https://www.suse.com/security/cve/CVE-2017-3738.html

https://bugzilla.suse.com/1071905

https://bugzilla.suse.com/1071906

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2017:3345-1
Rating: important
Affected Products: openSUSE Leap 42.3 openSUSE Leap 42.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here