openSUSE: 2020:2269-1 important: openssl-1_0_0
openSUSE: 2020:2269-1 important: openssl-1_0_0
An update that solves one vulnerability and has 6 fixes is now available.
openSUSE Security Update: Security update for openssl-1_0_0 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2269-1 Rating: important References: #1155346 #1176029 #1177479 #1177575 #1177673 #1177793 #1179491 Cross-References: CVE-2020-1971 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for openssl-1_0_0 fixes the following issues: - CVE-2020-1971: Fixed a null pointer dereference in EDIPARTYNAME (bsc#1179491). - Initialized dh->nid to NID_undef in DH_new_method() (bsc#1177673). - Fixed a test failure in apache_ssl in fips mode (bsc#1177793). - Renamed BN_get_rfc3526_prime_* functions back to get_rfc3526_prime_* (bsc#1177575). - Restored private key check in EC_KEY_check_key (bsc#1177479). - Added shared secret KAT to FIPS DH selftest (bsc#1176029). - Included ECDH/DH Requirements from SP800-56Arev3 (bsc#1176029). - Used SHA-2 in the RSA pairwise consistency check (bsc#1155346) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-2269=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libopenssl-1_0_0-devel-1.0.2p-lp151.5.20.1 libopenssl10-1.0.2p-lp151.5.20.1 libopenssl10-debuginfo-1.0.2p-lp151.5.20.1 libopenssl1_0_0-1.0.2p-lp151.5.20.1 libopenssl1_0_0-debuginfo-1.0.2p-lp151.5.20.1 libopenssl1_0_0-hmac-1.0.2p-lp151.5.20.1 libopenssl1_0_0-steam-1.0.2p-lp151.5.20.1 libopenssl1_0_0-steam-debuginfo-1.0.2p-lp151.5.20.1 openssl-1_0_0-1.0.2p-lp151.5.20.1 openssl-1_0_0-cavs-1.0.2p-lp151.5.20.1 openssl-1_0_0-cavs-debuginfo-1.0.2p-lp151.5.20.1 openssl-1_0_0-debuginfo-1.0.2p-lp151.5.20.1 openssl-1_0_0-debugsource-1.0.2p-lp151.5.20.1 - openSUSE Leap 15.1 (noarch): openssl-1_0_0-doc-1.0.2p-lp151.5.20.1 - openSUSE Leap 15.1 (x86_64): libopenssl-1_0_0-devel-32bit-1.0.2p-lp151.5.20.1 libopenssl1_0_0-32bit-1.0.2p-lp151.5.20.1 libopenssl1_0_0-32bit-debuginfo-1.0.2p-lp151.5.20.1 libopenssl1_0_0-hmac-32bit-1.0.2p-lp151.5.20.1 libopenssl1_0_0-steam-32bit-1.0.2p-lp151.5.20.1 libopenssl1_0_0-steam-32bit-debuginfo-1.0.2p-lp151.5.20.1 References: https://www.suse.com/security/cve/CVE-2020-1971.html https://bugzilla.suse.com/1155346 https://bugzilla.suse.com/1176029 https://bugzilla.suse.com/1177479 https://bugzilla.suse.com/1177575 https://bugzilla.suse.com/1177673 https://bugzilla.suse.com/1177793 https://bugzilla.suse.com/1179491 _______________________________________________ openSUSE Security Announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe, email This email address is being protected from spambots. You need JavaScript enabled to view it. List Netiquette: https://en.opensuse.org/openSUSE:Mailing_list_netiquette List Archives: https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it.