Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE 10 SP3 LTSS: SUSE-SU-2012:0674-1 Important OpenSSL DoS Issue

suse
Calendar Grey May 30, 2012
Scroller Suse
SUSE enhances openssl by resolving 10 critical vulnerabilities, addressing concerns like memory leaks and potential denial of service exploits.
An update that fixes 10 vulnerabilities is now available

Summary

This update of openssl fixes the following security issues: * Denial of Service or crash via CBC mode handling. (CVE-2012-2333 ) * Incorrect integer conversions that could result in memory corruption. (CVE-2012-2110 , CVE-2012-2131 ) * Potential memory leak in multithreaded key creation. * Symmetric crypto errors in PKCS7_decrypt. * Free headers after use in error message. * S/MIME verification may erroneously fail. * Tolerating bad MIME headers in ANS.1 parser. (CVE-2012-1165 , CVE-2006-7250

References

#739719 #742821 #748738 #749210 #749213 #749735

#751946 #758060 #761838

Cross- CVE-2006-7250 CVE-2011-4108 CVE-2011-4109

CVE-2011-4576 CVE-2011-4619 CVE-2012-0050

CVE-2012-1165 CVE-2012-2110 CVE-2012-2131

CVE-2012-2333

Affected Products:

SUSE Linux Enterprise Server 10 SP3 LTSS

https://www.suse.com/security/cve/CVE-2006-7250.html

https://www.suse.com/security/cve/CVE-2011-4108.html

https://www.suse.com/security/cve/CVE-2011-4109.html

https://www.suse.com/security/cve/CVE-2011-4576.html

https://www.suse.com/security/cve/CVE-2011-4619.html

https://www.suse.com/security/cve/CVE-2012-0050.html

https://www.suse.com/security/cve/CVE-2012-1165.html

https://www.suse.com/security/cve/CVE-2012-2110.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0674-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.