Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE: 2015:0553-1 Important: compat-openssl098 SSL Issues

suse
Calendar Grey March 20, 2015
Dist Suse Esm H88
SUSE Security Patch for compat-openssl098 addresses 8 vulnerabilities. This is a critical notice for outdated applications on SUSE Linux.
An update that fixes 8 vulnerabilities is now available

Summary

OpenSSL was updated to fix various security issues. Following security issues were fixed: - CVE-2015-0209: A Use After Free following d2i_ECPrivatekey error was fixed which could lead to crashes for attacker supplied Elliptic Curve keys. This could be exploited over SSL connections with client supplied keys. - CVE-2015-0286: A segmentation fault in ASN1_TYPE_cmp was fixed that could be exploited by attackers when e.g. client authentication is used. This could be exploited over SSL connections. - CVE-2015-0287: A ASN.1 structure reuse memory corruption was fixed. This problem can not be exploited over regular SSL connections, only if specific client programs use specific ASN.1 routines. - CVE-2015-0288: A X509_to_X509_REQ NULL pointer dereference was fixed,

References

#915976 #919648 #920236 #922488 #922496 #922499

#922500 #922501

Cross- CVE-2009-5146 CVE-2015-0209 CVE-2015-0286

CVE-2015-0287 CVE-2015-0288 CVE-2015-0289

CVE-2015-0292 CVE-2015-0293

Affected Products:

SUSE Linux Enterprise Module for Legacy Software 12

https://www.suse.com/security/cve/CVE-2009-5146.html

https://www.suse.com/security/cve/CVE-2015-0209.html

https://www.suse.com/security/cve/CVE-2015-0286.html

https://www.suse.com/security/cve/CVE-2015-0287.html

https://www.suse.com/security/cve/CVE-2015-0288.html

https://www.suse.com/security/cve/CVE-2015-0289.html

https://www.suse.com/security/cve/CVE-2015-0292.html

https://www.suse.com/security/cve/CVE-2015-0293.html

https://bugzilla.suse.com/show_bug.cgi?id=915976

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0553-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here