Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE 11-SP4: 2016:2458-1 Important: OpenSSL Memory Growth and DoS

suse
Calendar Grey October 5, 2016
Dist Suse Esm H88
This significant announcement covers 10 critical concerns with OpenSSL, such as memory leaks and risks of Denial of Service attacks.
An update that solves 10 vulnerabilities and has four fixes An update that solves 10 vulnerabilities and has four fixes An update that solves 10 vulnerabilities and has four fixes ...

Summary

This update for openssl fixes the following issues: OpenSSL Security Advisory [22 Sep 2016] (bsc#999665) Severity: High * OCSP Status Request extension unbounded memory growth (CVE-2016-6304) (bsc#999666) Severity: Low * Pointer arithmetic undefined behavior (CVE-2016-2177) (bsc#982575) * Constant time flag not preserved in DSA signing (CVE-2016-2178) (bsc#983249) * DTLS buffered message DoS (CVE-2016-2179) (bsc#994844) * DTLS replay protection DoS (CVE-2016-2181) (bsc#994749) * OOB write in BN_bn2dec() (CVE-2016-2182) (bsc#993819) * Birthday attack against 64-bit block ciphers (SWEET32) (CVE-2016-2183) (bsc#995359) * Malformed SHA512 ticket DoS (CVE-2016-6302) (bsc#995324) * OOB write in MDC2_Update() (CVE-2016-6303) (bsc#995377)

References

#979475 #982575 #983249 #993819 #994749 #994844

#995075 #995324 #995359 #995377 #998190 #999665

#999666 #999668

Cross- CVE-2016-2177 CVE-2016-2178 CVE-2016-2179

CVE-2016-2181 CVE-2016-2182 CVE-2016-2183

CVE-2016-6302 CVE-2016-6303 CVE-2016-6304

CVE-2016-6306

Affected Products:

SUSE Studio Onsite 1.3

SUSE OpenStack Cloud 5

SUSE Manager Proxy 2.1

SUSE Manager 2.1

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

SUSE ...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2458-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here