Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2016:1206-1 Important: OpenSSL1 Memory Corruption Fixes

suse
Calendar Grey May 3, 2016
Scroller Suse
SUSE enhances openssl1 to resolve five severe vulnerabilities, focusing on memory corruption and padding oracle issues.
An update that solves 5 vulnerabilities and has four fixes An update that solves 5 vulnerabilities and has four fixes An update that solves 5 vulnerabilities and has four fixes is ...

Summary

This update for openssl1 fixes the following issues: Security issues fixed: - CVE-2016-2108: Memory corruption in the ASN.1 encoder (bsc#977617) - CVE-2016-2107: Padding oracle in AES-NI CBC MAC check (bsc#977616) - CVE-2016-2105: EVP_EncodeUpdate overflow (bsc#977614) - CVE-2016-2106: EVP_EncryptUpdate overflow (bsc#977615) - CVE-2016-2109: ASN.1 BIO excessive memory allocation (bsc#976942) Bugs fixed: - bsc#971354: libopenssl1_0_0 now Recommends: openssl1 to get correct SSL Root Certificate hashes - bsc#889013: Rename README.SuSE to the new spelling README.SUSE - bsc#976943: Fixed a buffer overrun in ASN1_parse. - bsc#977621: Preserve negotiated digests for SNI (bsc#977621) Patch Instructions: To install this SUSE Security Update use YaST online_update.

References

#889013 #971354 #976942 #976943 #977614 #977615

#977616 #977617 #977621

Cross- CVE-2016-2105 CVE-2016-2106 CVE-2016-2107

CVE-2016-2108 CVE-2016-2109

Affected Products:

SUSE Linux Enterprise Server 11-SECURITY

https://www.suse.com/security/cve/CVE-2016-2105.html

https://www.suse.com/security/cve/CVE-2016-2106.html

https://www.suse.com/security/cve/CVE-2016-2107.html

https://www.suse.com/security/cve/CVE-2016-2108.html

https://www.suse.com/security/cve/CVE-2016-2109.html

https://bugzilla.suse.com/889013

https://bugzilla.suse.com/971354

https://bugzilla.suse.com/976942

https://bugzilla.suse.com/976943

https://bugzilla.suse.com/977614

https://bugzilla.suse.com/977615

https://bugzilla.suse.com/977616

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1206-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.