Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

SUSE Linux Enterprise 11 SP3 SUSE-SU-2014:0762-1 Critical OpenSSL Update

suse
Calendar Grey June 6, 2014
Scroller Suse
Important patch released for OpenSSL 1.0 on SUSE Linux resolving multiple security flaws, notably denial-of-service vulnerabilities.
An update that fixes 5 vulnerabilities is now available

Summary

OpenSSL was updated to fix several vulnerabilities: * SSL/TLS MITM vulnerability. (CVE-2014-0224) * DTLS recursion flaw. (CVE-2014-0221) * DTLS invalid fragment vulnerability. (CVE-2014-0195) * SSL_MODE_RELEASE_BUFFERS NULL pointer dereference. (CVE-2014-0198) * Anonymous ECDH denial of service. (CVE-2014-3470) Further information can be found at . Security Issues references: * CVE-2014-0224 * CVE-2014-0221 * CVE-2014-0195 * CVE-2014-0198

References

#876282 #880891

Cross- CVE-2014-0195 CVE-2014-0198 CVE-2014-0221

CVE-2014-0224 CVE-2014-3470

Affected Products:

SUSE Linux Enterprise Security Module 11 SP3

https://www.suse.com/security/cve/CVE-2014-0195.html

https://www.suse.com/security/cve/CVE-2014-0198.html

https://www.suse.com/security/cve/CVE-2014-0221.html

https://www.suse.com/security/cve/CVE-2014-0224.html

https://www.suse.com/security/cve/CVE-2014-3470.html

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0762-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.