Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2021:4592-1 Critical: OpenSSL Vulnerabilities Mitigation

suse
Calendar Grey May 11, 2016
Dist Suse Esm H88
SUSE Security Patch for openssl addresses major vulnerabilities enhancing system reliability and improving encryption standards.
An update that fixes 12 vulnerabilities is now available

Summary

This update for ntp to 4.2.8p7 fixes the following issues: * CVE-2016-1547, bsc#977459: Validate crypto-NAKs, AKA: CRYPTO-NAK DoS. * CVE-2016-1548, bsc#977461: Interleave-pivot * CVE-2016-1549, bsc#977451: Sybil vulnerability: ephemeral association attack. * CVE-2016-1550, bsc#977464: Improve NTP security against buffer comparison timing attacks. * CVE-2016-1551, bsc#977450: Refclock impersonation vulnerability * CVE-2016-2516, bsc#977452: Duplicate IPs on unconfig directives will cause an assertion botch in ntpd. * CVE-2016-2517, bsc#977455: remote configuration trustedkey/ requestkey/controlkey values are not properly validated. * CVE-2016-2518, bsc#977457: Crafted addpeer with hmode > 7 causes array wraparound with MATCH_ASSOC.

References

#957226 #977446 #977450 #977451 #977452 #977455

#977457 #977458 #977459 #977461 #977464

Cross- CVE-2015-7704 CVE-2015-7705 CVE-2015-7974

CVE-2016-1547 CVE-2016-1548 CVE-2016-1549

CVE-2016-1550 CVE-2016-1551 CVE-2016-2516

CVE-2016-2517 CVE-2016-2518 CVE-2016-2519

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2015-7704.html

https://www.suse.com/security/cve/CVE-2015-7705.html

https://www.suse.com/security/cve/CVE-2015-7974.html

https://www.suse.com/security/cve/CVE-2016-1547.html

https://www.suse.com/security/cve/CVE-2016-1548.html

https://www.suse.com/security/cve/CVE-2016-1549.html

https://www.suse.com/security/cve/CVE-2016-1550.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1278-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here