[SUSE-SU-2015:1182-2] Security update for OpenSSL

Severity Moderate
Affected Packages 32
CVEs 33

Security update for OpenSSL

This OpenSSL update fixes the following issues:

* Session Ticket Memory Leak (CVE-2014-3567)
* Build option no-ssl3 is incomplete (CVE-2014-3568)
* Add support for TLS_FALLBACK_SCSV to mitigate CVE-2014-3566 (POODLE)

Security Issues:

* CVE-2014-3567
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3567>
* CVE-2014-3566
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566>
* CVE-2014-3568
  <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3568>
Package Affected Version
pkg:rpm/suse/openssl?arch=x86_64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl?arch=x86_64&distro=sled-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl?arch=s390x&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl?arch=ppc64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl?arch=ia64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl?arch=i586&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl?arch=i586&distro=sled-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl-doc?arch=x86_64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl-doc?arch=s390x&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl-doc?arch=ppc64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl-doc?arch=ia64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/openssl-doc?arch=i586&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8?arch=x86_64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8?arch=x86_64&distro=sled-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8?arch=s390x&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8?arch=ppc64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8?arch=ia64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8?arch=i586&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8?arch=i586&distro=sled-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-x86?arch=ia64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac?arch=x86_64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac?arch=s390x&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac?arch=ppc64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac?arch=ia64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac?arch=i586&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac-32bit?arch=x86_64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac-32bit?arch=s390x&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-hmac-32bit?arch=ppc64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-32bit?arch=x86_64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-32bit?arch=x86_64&distro=sled-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-32bit?arch=s390x&distro=sles-11&sp=3 < 0.9.8j-0.66.1
pkg:rpm/suse/libopenssl0_9_8-32bit?arch=ppc64&distro=sles-11&sp=3 < 0.9.8j-0.66.1
ID
SUSE-SU-2015:1182-2
Severity
moderate
URL
https://www.suse.com/support/update/announcement/2015/suse-su-20151182-2/
Published
2014-10-24T22:07:03
(10 years ago)
Modified
2014-10-24T22:07:03
(10 years ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/suse-su-2015_1182-2.json
Suse URL for SUSE-SU-2015:1182-2 https://www.suse.com/support/update/announcement/2015/suse-su-20151182-2/
Suse E-Mail link for SUSE-SU-2015:1182-2 https://lists.suse.com/pipermail/sle-security-updates/2015-July/001481.html
Bugzilla SUSE Bug 859228 https://bugzilla.suse.com/859228
Bugzilla SUSE Bug 859924 https://bugzilla.suse.com/859924
Bugzilla SUSE Bug 860332 https://bugzilla.suse.com/860332
Bugzilla SUSE Bug 862181 https://bugzilla.suse.com/862181
Bugzilla SUSE Bug 869945 https://bugzilla.suse.com/869945
Bugzilla SUSE Bug 870192 https://bugzilla.suse.com/870192
Bugzilla SUSE Bug 879179 https://bugzilla.suse.com/879179
Bugzilla SUSE Bug 880891 https://bugzilla.suse.com/880891
Bugzilla SUSE Bug 890764 https://bugzilla.suse.com/890764
Bugzilla SUSE Bug 890767 https://bugzilla.suse.com/890767
Bugzilla SUSE Bug 890768 https://bugzilla.suse.com/890768
Bugzilla SUSE Bug 890769 https://bugzilla.suse.com/890769
Bugzilla SUSE Bug 890770 https://bugzilla.suse.com/890770
Bugzilla SUSE Bug 892403 https://bugzilla.suse.com/892403
Bugzilla SUSE Bug 901223 https://bugzilla.suse.com/901223
Bugzilla SUSE Bug 901277 https://bugzilla.suse.com/901277
Bugzilla SUSE Bug 912014 https://bugzilla.suse.com/912014
Bugzilla SUSE Bug 912015 https://bugzilla.suse.com/912015
Bugzilla SUSE Bug 912018 https://bugzilla.suse.com/912018
Bugzilla SUSE Bug 912293 https://bugzilla.suse.com/912293
Bugzilla SUSE Bug 912294 https://bugzilla.suse.com/912294
Bugzilla SUSE Bug 912296 https://bugzilla.suse.com/912296
Bugzilla SUSE Bug 915976 https://bugzilla.suse.com/915976
Bugzilla SUSE Bug 919648 https://bugzilla.suse.com/919648
Bugzilla SUSE Bug 920236 https://bugzilla.suse.com/920236
Bugzilla SUSE Bug 922488 https://bugzilla.suse.com/922488
Bugzilla SUSE Bug 922496 https://bugzilla.suse.com/922496
Bugzilla SUSE Bug 922499 https://bugzilla.suse.com/922499
Bugzilla SUSE Bug 922500 https://bugzilla.suse.com/922500
Bugzilla SUSE Bug 922501 https://bugzilla.suse.com/922501
Bugzilla SUSE Bug 929678 https://bugzilla.suse.com/929678
Bugzilla SUSE Bug 931698 https://bugzilla.suse.com/931698
Bugzilla SUSE Bug 933898 https://bugzilla.suse.com/933898
Bugzilla SUSE Bug 933911 https://bugzilla.suse.com/933911
Bugzilla SUSE Bug 934487 https://bugzilla.suse.com/934487
Bugzilla SUSE Bug 934489 https://bugzilla.suse.com/934489
Bugzilla SUSE Bug 934491 https://bugzilla.suse.com/934491
Bugzilla SUSE Bug 934493 https://bugzilla.suse.com/934493
CVE SUSE CVE CVE-2009-5146 page https://www.suse.com/security/cve/CVE-2009-5146/
CVE SUSE CVE CVE-2014-0076 page https://www.suse.com/security/cve/CVE-2014-0076/
CVE SUSE CVE CVE-2014-0221 page https://www.suse.com/security/cve/CVE-2014-0221/
CVE SUSE CVE CVE-2014-0224 page https://www.suse.com/security/cve/CVE-2014-0224/
CVE SUSE CVE CVE-2014-3470 page https://www.suse.com/security/cve/CVE-2014-3470/
CVE SUSE CVE CVE-2014-3505 page https://www.suse.com/security/cve/CVE-2014-3505/
CVE SUSE CVE CVE-2014-3506 page https://www.suse.com/security/cve/CVE-2014-3506/
CVE SUSE CVE CVE-2014-3507 page https://www.suse.com/security/cve/CVE-2014-3507/
CVE SUSE CVE CVE-2014-3508 page https://www.suse.com/security/cve/CVE-2014-3508/
CVE SUSE CVE CVE-2014-3510 page https://www.suse.com/security/cve/CVE-2014-3510/
CVE SUSE CVE CVE-2014-3566 page https://www.suse.com/security/cve/CVE-2014-3566/
CVE SUSE CVE CVE-2014-3567 page https://www.suse.com/security/cve/CVE-2014-3567/
CVE SUSE CVE CVE-2014-3568 page https://www.suse.com/security/cve/CVE-2014-3568/
CVE SUSE CVE CVE-2014-3570 page https://www.suse.com/security/cve/CVE-2014-3570/
CVE SUSE CVE CVE-2014-3571 page https://www.suse.com/security/cve/CVE-2014-3571/
CVE SUSE CVE CVE-2014-3572 page https://www.suse.com/security/cve/CVE-2014-3572/
CVE SUSE CVE CVE-2014-8275 page https://www.suse.com/security/cve/CVE-2014-8275/
CVE SUSE CVE CVE-2015-0204 page https://www.suse.com/security/cve/CVE-2015-0204/
CVE SUSE CVE CVE-2015-0205 page https://www.suse.com/security/cve/CVE-2015-0205/
CVE SUSE CVE CVE-2015-0209 page https://www.suse.com/security/cve/CVE-2015-0209/
CVE SUSE CVE CVE-2015-0286 page https://www.suse.com/security/cve/CVE-2015-0286/
CVE SUSE CVE CVE-2015-0287 page https://www.suse.com/security/cve/CVE-2015-0287/
CVE SUSE CVE CVE-2015-0288 page https://www.suse.com/security/cve/CVE-2015-0288/
CVE SUSE CVE CVE-2015-0289 page https://www.suse.com/security/cve/CVE-2015-0289/
CVE SUSE CVE CVE-2015-0292 page https://www.suse.com/security/cve/CVE-2015-0292/
CVE SUSE CVE CVE-2015-0293 page https://www.suse.com/security/cve/CVE-2015-0293/
CVE SUSE CVE CVE-2015-1788 page https://www.suse.com/security/cve/CVE-2015-1788/
CVE SUSE CVE CVE-2015-1789 page https://www.suse.com/security/cve/CVE-2015-1789/
CVE SUSE CVE CVE-2015-1790 page https://www.suse.com/security/cve/CVE-2015-1790/
CVE SUSE CVE CVE-2015-1791 page https://www.suse.com/security/cve/CVE-2015-1791/
CVE SUSE CVE CVE-2015-1792 page https://www.suse.com/security/cve/CVE-2015-1792/
CVE SUSE CVE CVE-2015-3216 page https://www.suse.com/security/cve/CVE-2015-3216/
CVE SUSE CVE CVE-2015-4000 page https://www.suse.com/security/cve/CVE-2015-4000/
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/openssl?arch=x86_64&distro=sles-11&sp=3 suse openssl < 0.9.8j-0.66.1 sles-11 x86_64
Affected pkg:rpm/suse/openssl?arch=x86_64&distro=sled-11&sp=3 suse openssl < 0.9.8j-0.66.1 sled-11 x86_64
Affected pkg:rpm/suse/openssl?arch=s390x&distro=sles-11&sp=3 suse openssl < 0.9.8j-0.66.1 sles-11 s390x
Affected pkg:rpm/suse/openssl?arch=ppc64&distro=sles-11&sp=3 suse openssl < 0.9.8j-0.66.1 sles-11 ppc64
Affected pkg:rpm/suse/openssl?arch=ia64&distro=sles-11&sp=3 suse openssl < 0.9.8j-0.66.1 sles-11 ia64
Affected pkg:rpm/suse/openssl?arch=i586&distro=sles-11&sp=3 suse openssl < 0.9.8j-0.66.1 sles-11 i586
Affected pkg:rpm/suse/openssl?arch=i586&distro=sled-11&sp=3 suse openssl < 0.9.8j-0.66.1 sled-11 i586
Affected pkg:rpm/suse/openssl-doc?arch=x86_64&distro=sles-11&sp=3 suse openssl-doc < 0.9.8j-0.66.1 sles-11 x86_64
Affected pkg:rpm/suse/openssl-doc?arch=s390x&distro=sles-11&sp=3 suse openssl-doc < 0.9.8j-0.66.1 sles-11 s390x
Affected pkg:rpm/suse/openssl-doc?arch=ppc64&distro=sles-11&sp=3 suse openssl-doc < 0.9.8j-0.66.1 sles-11 ppc64
Affected pkg:rpm/suse/openssl-doc?arch=ia64&distro=sles-11&sp=3 suse openssl-doc < 0.9.8j-0.66.1 sles-11 ia64
Affected pkg:rpm/suse/openssl-doc?arch=i586&distro=sles-11&sp=3 suse openssl-doc < 0.9.8j-0.66.1 sles-11 i586
Affected pkg:rpm/suse/libopenssl0_9_8?arch=x86_64&distro=sles-11&sp=3 suse libopenssl0_9_8 < 0.9.8j-0.66.1 sles-11 x86_64
Affected pkg:rpm/suse/libopenssl0_9_8?arch=x86_64&distro=sled-11&sp=3 suse libopenssl0_9_8 < 0.9.8j-0.66.1 sled-11 x86_64
Affected pkg:rpm/suse/libopenssl0_9_8?arch=s390x&distro=sles-11&sp=3 suse libopenssl0_9_8 < 0.9.8j-0.66.1 sles-11 s390x
Affected pkg:rpm/suse/libopenssl0_9_8?arch=ppc64&distro=sles-11&sp=3 suse libopenssl0_9_8 < 0.9.8j-0.66.1 sles-11 ppc64
Affected pkg:rpm/suse/libopenssl0_9_8?arch=ia64&distro=sles-11&sp=3 suse libopenssl0_9_8 < 0.9.8j-0.66.1 sles-11 ia64
Affected pkg:rpm/suse/libopenssl0_9_8?arch=i586&distro=sles-11&sp=3 suse libopenssl0_9_8 < 0.9.8j-0.66.1 sles-11 i586
Affected pkg:rpm/suse/libopenssl0_9_8?arch=i586&distro=sled-11&sp=3 suse libopenssl0_9_8 < 0.9.8j-0.66.1 sled-11 i586
Affected pkg:rpm/suse/libopenssl0_9_8-x86?arch=ia64&distro=sles-11&sp=3 suse libopenssl0_9_8-x86 < 0.9.8j-0.66.1 sles-11 ia64
Affected pkg:rpm/suse/libopenssl0_9_8-hmac?arch=x86_64&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac < 0.9.8j-0.66.1 sles-11 x86_64
Affected pkg:rpm/suse/libopenssl0_9_8-hmac?arch=s390x&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac < 0.9.8j-0.66.1 sles-11 s390x
Affected pkg:rpm/suse/libopenssl0_9_8-hmac?arch=ppc64&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac < 0.9.8j-0.66.1 sles-11 ppc64
Affected pkg:rpm/suse/libopenssl0_9_8-hmac?arch=ia64&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac < 0.9.8j-0.66.1 sles-11 ia64
Affected pkg:rpm/suse/libopenssl0_9_8-hmac?arch=i586&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac < 0.9.8j-0.66.1 sles-11 i586
Affected pkg:rpm/suse/libopenssl0_9_8-hmac-32bit?arch=x86_64&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac-32bit < 0.9.8j-0.66.1 sles-11 x86_64
Affected pkg:rpm/suse/libopenssl0_9_8-hmac-32bit?arch=s390x&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac-32bit < 0.9.8j-0.66.1 sles-11 s390x
Affected pkg:rpm/suse/libopenssl0_9_8-hmac-32bit?arch=ppc64&distro=sles-11&sp=3 suse libopenssl0_9_8-hmac-32bit < 0.9.8j-0.66.1 sles-11 ppc64
Affected pkg:rpm/suse/libopenssl0_9_8-32bit?arch=x86_64&distro=sles-11&sp=3 suse libopenssl0_9_8-32bit < 0.9.8j-0.66.1 sles-11 x86_64
Affected pkg:rpm/suse/libopenssl0_9_8-32bit?arch=x86_64&distro=sled-11&sp=3 suse libopenssl0_9_8-32bit < 0.9.8j-0.66.1 sled-11 x86_64
Affected pkg:rpm/suse/libopenssl0_9_8-32bit?arch=s390x&distro=sles-11&sp=3 suse libopenssl0_9_8-32bit < 0.9.8j-0.66.1 sles-11 s390x
Affected pkg:rpm/suse/libopenssl0_9_8-32bit?arch=ppc64&distro=sles-11&sp=3 suse libopenssl0_9_8-32bit < 0.9.8j-0.66.1 sles-11 ppc64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...