Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2015:0541-1 Important: OpenSSL Critical Denial of Service Fixes

suse
Calendar Grey March 19, 2015
Dist Suse Esm H88
Urgent Fedora patch addresses 5 major open-source flaws posing serious risks. Learn more within!
An update that fixes 6 vulnerabilities is now available

Summary

OpenSSL was updated to fix various security issues. Following security issues were fixed: - CVE-2015-0209: A Use After Free following d2i_ECPrivatekey error was fixed which could lead to crashes for attacker supplied Elliptic Curve keys. This could be exploited over SSL connections with client supplied keys. - CVE-2015-0286: A segmentation fault in ASN1_TYPE_cmp was fixed that could be exploited by attackers when e.g. client authentication is used. This could be exploited over SSL connections. - CVE-2015-0287: A ASN.1 structure reuse memory corruption was fixed. This problem can not be exploited over regular SSL connections, only if specific client programs use specific ASN.1 routines. - CVE-2015-0288: A X509_to_X509_REQ NULL pointer dereference was fixed,

References

#919648 #920236 #922488 #922496 #922499 #922500

Cross- CVE-2015-0209 CVE-2015-0286 CVE-2015-0287

CVE-2015-0288 CVE-2015-0289 CVE-2015-0293

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-0209.html

https://www.suse.com/security/cve/CVE-2015-0286.html

https://www.suse.com/security/cve/CVE-2015-0287.html

https://www.suse.com/security/cve/CVE-2015-0288.html

https://www.suse.com/security/cve/CVE-2015-0289.html

https://www.suse.com/security/cve/CVE-2015-0293.html

https://bugzilla.suse.com/show_bug.cgi?id=919648

https://bugzilla.suse.com/show_bug.cgi?id=920236

https://bugzilla.suse.com/show_bug.cgi?id=922488

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0541-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here