Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2018:2545-1 Moderate: OpenSSL1 Key Generation Risk

suse
Calendar Grey August 28, 2018
Dist Suse Esm H88
SUSE has released a security update for openssl1, addressing vulnerabilities: moderate severity, denial of service risks, and cache timing attacks.
An update that solves two vulnerabilities and has two fixes is now available

Summary

This update for openssl1 fixes the following security issues: - CVE-2018-0737: The RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could have recovered the private key (bsc#1089039) - CVE-2018-0732: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server could have sent a very large prime value to the client. This caused the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack (bsc#1097158) - Blinding enhancements for ECDSA and DSA (bsc#1097624, bsc#1098592) Patch Instructions:

References

#1089039 #1097158 #1097624 #1098592

Cross- CVE-2018-0732 CVE-2018-0737

Affected Products:

SUSE Linux Enterprise Server 11-SECURITY

https://www.suse.com/security/cve/CVE-2018-0732.html

https://www.suse.com/security/cve/CVE-2018-0737.html

https://bugzilla.suse.com/1089039

https://bugzilla.suse.com/1097158

https://bugzilla.suse.com/1097624

https://bugzilla.suse.com/1098592

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2545-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here