Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

SUSE CORE 9: 2014:0768-1 Critical: OpenSSL MITM Issue And Key Leak

suse
Calendar Grey June 7, 2014
Scroller Suse
SUSE Security Update for OpenSSL addresses severe vulnerabilities, such as a potential MAN-IN-THE-MIDDLE exploit and unintentional exposure of ECC private keys.
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

OpenSSL was updated to fix the following security vulnerabilities: * SSL/TLS MITM vulnerability. (CVE-2014-0224) * ECC private key can leak on 32 bit platforms. (CVE-2011-4354) Further information can be found at . Security Issues references: * CVE-2014-0224 * CVE-2011-4354 Package List: - SUSE CORE 9 (i586 s390 s390x x86_64): openssl-0.9.7d-15.50 openssl-devel-0.9.7d-15.50 openssl-doc-0.9.7d-15.50 - SUSE CORE 9 (x86_64): openssl-32bit-9-201406041231 openssl-devel-32bit-9-201406041231 - SUSE CORE 9 (s390x): openssl-32bit-9-201406060130 openssl-devel-32bit-9-201406060130

References

#459468 #489641 #880891

Cross- CVE-2011-4354 CVE-2014-0224

Affected Products:

SUSE CORE 9

https://www.suse.com/security/cve/CVE-2011-4354.html

https://www.suse.com/security/cve/CVE-2014-0224.html

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0768-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.