Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2018:4274-1 Moderate: OpenSSL Timing Attack Enhancements

suse
Calendar Grey December 27, 2018
Dist Suse Esm H88
Fortify your infrastructure using SUSE's newest OpenSSL patches that resolve three urgent vulnerabilities. Maintain your defenses against potential threats!
An update that solves three vulnerabilities and has one errata is now available

Summary

This update for openssl fixes the following issues: Security issues fixed: - CVE-2018-0734: Fixed timing vulnerability in DSA signature generation (bsc#1113652). - CVE-2018-5407: Fixed elliptic curve scalar multiplication timing attack defenses (bsc#1113534). - CVE-2016-8610: Adjusted current fix and add missing error string (bsc#1110018). - Fixed the "One and Done" side-channel attack on RSA (bsc#1104789). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.3: zypper in -t patch slestso13-openssl-13918=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-openssl-13918=1

References

#1104789 #1110018 #1113534 #1113652

Cross- CVE-2016-8610 CVE-2018-0734 CVE-2018-5407

Affected Products:

SUSE Studio Onsite 1.3

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2016-8610.html

https://www.suse.com/security/cve/CVE-2018-0734.html

https://www.suse.com/security/cve/CVE-2018-5407.html

https://bugzilla.suse.com/1104789

https://bugzilla.suse.com/1110018

https://bugzilla.suse.com/1113534

https://bugzilla.suse.com/1113652

Announcement ID: SUSE-SU-2018:4274-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here