OpenSSL was updated to fix various security issues. Following security issues were fixed: - CVE-2015-0209: A Use After Free following d2i_ECPrivatekey error was fixed which could lead to crashes for attacker supplied Elliptic Curve keys. This could be exploited over SSL connections with client supplied keys. - CVE-2015-0286: A segmentation fault in ASN1_TYPE_cmp was fixed that could be exploited by attackers when e.g. client authentication is used. This could be exploited over SSL connections. - CVE-2015-0287: A ASN.1 structure reuse memory corruption was fixed. This problem can not be exploited over regular SSL connections, only if specific client programs use specific ASN.1 routines. - CVE-2015-0288: A X509_to_X509_REQ NULL pointer dereference was fixed,
#919648 #920236 #922488 #922496 #922499 #922500
Cross- CVE-2015-0209 CVE-2015-0286 CVE-2015-0287
CVE-2015-0288 CVE-2015-0289 CVE-2015-0293
Affected Products:
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 12
https://www.suse.com/security/cve/CVE-2015-0209.html
https://www.suse.com/security/cve/CVE-2015-0286.html
https://www.suse.com/security/cve/CVE-2015-0287.html
https://www.suse.com/security/cve/CVE-2015-0288.html
https://www.suse.com/security/cve/CVE-2015-0289.html
https://www.suse.com/security/cve/CVE-2015-0293.html
https://bugzilla.suse.com/show_bug.cgi?id=919648
https://bugzilla.suse.com/show_bug.cgi?id=920236
https://bugzilla.suse.com/show_bug.cgi?id=922488
Get the latest Linux and open source security news straight to your inbox.