Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 438
Alerts This Week
Warning Icon 1 438

SUSE: 2014:0759-1 Critical: OpenSSL Update Against DoS Threats

suse
Calendar Grey June 6, 2014
Scroller Suse
Critical SUSE patch for OpenSSL tackles significant vulnerabilities, exposing threats such as denial-of-service and man-in-the-middle attacks.
An update that fixes three vulnerabilities is now available

Summary

OpenSSL was updated to fix several vulnerabilities: * SSL/TLS MITM vulnerability. (CVE-2014-0224) * DTLS recursion flaw. (CVE-2014-0221) * Anonymous ECDH denial of service. (CVE-2014-3470) Further information can be found at . Security Issues references: * CVE-2014-0224 * CVE-2014-0221 * CVE-2014-3470 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP3:

References

#880891

Cross- CVE-2014-0221 CVE-2014-0224 CVE-2014-3470

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-0221.html

https://www.suse.com/security/cve/CVE-2014-0224.html

https://www.suse.com/security/cve/CVE-2014-3470.html

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0759-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.