Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2012:0085-1 Critical: GnuTLS Vulnerability And Mitigation Updates

suse
Calendar Grey January 16, 2012
Dist Suse Esm H88
Critical patch released for OpenSSL via SUSE addresses 5 major vulnerabilities. Ensure your systems are secure by implementing the newest updates promptly.
An update that fixes 5 vulnerabilities is now available

Summary

Various security vulnerabilities have been fixed in OpenSSL: * DTLS plaintext recovery attack (CVE-2011-4108) * double-free in Policy Checks (CVE-2011-4109) * uninitialized SSL 3.0 padding (CVE-2011-4576) * malformed RFC 3779 data can cause assertion failures (CVE-2011-4577) * SGC restart DoS attack (CVE-2011-4619) Security Issue references: * CVE-2011-4108 * CVE-2011-4109 * CVE-2011-4576 * CVE-2011-4577 * CVE-2011-4619

References

#739719

Cross- CVE-2011-4108 CVE-2011-4109 CVE-2011-4576

CVE-2011-4577 CVE-2011-4619

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP1

SUSE Linux Enterprise Server 11 SP1 for VMware

SUSE Linux Enterprise Server 11 SP1

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 11 SP1

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://www.suse.com/security/cve/CVE-2011-4108.html

https://www.suse.com/security/cve/CVE-2011-4109.html

https://www.suse.com/security/cve/CVE-2011-4576.html

https://www.suse.com/security/cve/CVE-2011-4577.html

https://www.suse.com/security/cve/CVE-2011-4619.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0084-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here