An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for openssl-1_1 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3890-1 Rating: moderate References: #1113651 #1113652 Cross-References: CVE-2018-0734 CVE-2018-0735 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for openssl-1_1 fixes the following issues: Security issues fixed: - CVE-2018-0734: timing vulnerability in DSA signature generation (bsc#1113652). - CVE-2018-0735: timing vulnerability in ECDSA signature generation (bsc#1113651). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1465=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libopenssl-1_1-devel-1.1.0i-lp150.3.15.1 libopenssl1_1-1.1.0i-lp150.3.15.1 libopenssl1_1-debuginfo-1.1.0i-lp150.3.15.1 libopenssl1_1-hmac-1.1.0i-lp150.3.15.1 openssl-1_1-1.1.0i-lp150.3.15.1 openssl-1_1-debuginfo-1.1.0i-lp150.3.15.1 openssl-1_1-debugsource-1.1.0i-lp150.3.15.1 - openSUSE Leap 15.0 (noarch): openssl-1_1-doc-1.1.0i-lp150.3.15.1 - openSUSE Leap 15.0 (x86_64): libopenssl-1_1-devel-32bit-1.1.0i-lp150.3.15.1 libopenssl1_1-32bit-1.1.0i-lp150.3.15.1 libopenssl1_1-32bit-debuginfo-1.1.0i-lp150.3.15.1 libopenssl1_1-hmac-32bit-1.1.0i-lp150.3.15.1 References: https://www.suse.com/security/cve/CVE-2018-0734.html https://www.suse.com/security/cve/CVE-2018-0735.html https://bugzilla.suse.com/1113651 https://bugzilla.suse.com/1113652 -- . This release corrects notable performance delays in openssl-1_2 for openSUSE Leap 15.1, improving stability.. OpenSSL Update, openSUSE Security, security patches. . LinuxSecurity.com Team
A covert timing channel flaw was found in the way OpenSSH handled authentication of non-existent users. A remote unauthenticated attacker could possibly use this flaw to determine valid user names by measuring the timing of server responses. (CVE-2016-6210) SL6 x86_64 openssh-5.3p1-123.el6_9.x86_64.rpm openssh-askpass-5.3p1-123.el6_9.x86_64.rpm openssh-clients-5.3p1-123.el6_9.x8 [More...]. Synopsis: Moderate: openssh security update Advisory ID: SLSA-2017:2563-1 Issue Date: 2017-08-31 CVE Numbers: CVE-2016-6210 -- Security Fix(es): * A covert timing channel flaw was found in the way OpenSSH handled authentication of non-existent users. A remote unauthenticated attacker could possibly use this flaw to determine valid user names by measuring the timing of server responses. (CVE-2016-6210) -- SL6 x86_64 openssh-5.3p1-123.el6_9.x86_64.rpm openssh-askpass-5.3p1-123.el6_9.x86_64.rpm openssh-clients-5.3p1-123.el6_9.x86_64.rpm openssh-debuginfo-5.3p1-123.el6_9.x86_64.rpm openssh-server-5.3p1-123.el6_9.x86_64.rpm openssh-debuginfo-5.3p1-123.el6_9.i686.rpm openssh-ldap-5.3p1-123.el6_9.x86_64.rpm pam_ssh_agent_auth-0.9.3-123.el6_9.i686.rpm pam_ssh_agent_auth-0.9.3-123.el6_9.x86_64.rpm i386 openssh-5.3p1-123.el6_9.i686.rpm openssh-askpass-5.3p1-123.el6_9.i686.rpm openssh-clients-5.3p1-123.el6_9.i686.rpm openssh-debuginfo-5.3p1-123.el6_9.i686.rpm openssh-server-5.3p1-123.el6_9.i686.rpm openssh-ldap-5.3p1-123.el6_9.i686.rpm pam_ssh_agent_auth-0.9.3-123.el6_9.i686.rpm - Scientific Linux Development Team . A recent security patch for OpenSSH rectifies a timing vulnerability that influences the verification process for non-existent accounts.. openssh security update, timing channel flaw, user authentication issue. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.