SUSE-SU-2015:0545-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-1
Summary: Security update for OpenSSL
Details: OpenSSL has been updated to fix several security issues: * CVE-2012-4929: Avoid the openssl CRIME attack by disabling SSL compression by default. Setting the environment variable 'OPENSSL_NO_DEFAULT_ZLIB' to 'no' enables compression again. * CVE-2013-0169: Timing attacks against TLS could be used by physically local attackers to gain access to transmitted plain text or private keymaterial. This issue is also known as the 'Lucky-13' issue. * CVE-2013-0166: A OCSP invalid key denial of service issue was fixed. Security Issue references: * CVE-2013-0169 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0169> * CVE-2013-0166 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0166>
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150545-1/, https://bugzilla.suse.com/779952, https://bugzilla.suse.com/802648, https://bugzilla.suse.com/802746, https://bugzilla.suse.com/859228, https://bugzilla.suse.com/859924, https://bugzilla.suse.com/860332, https://bugzilla.suse.com/862181, https://bugzilla.suse.com/869945, https://bugzilla.suse.com/870192, https://bugzilla.suse.com/880891, https://bugzilla.suse.com/890764, https://bugzilla.suse.com/890767, https://bugzilla.suse.com/890768, https://bugzilla.suse.com/890769, https://bugzilla.suse.com/890770, https://bugzilla.suse.com/892403, https://bugzilla.suse.com/901223, https://bugzilla.suse.com/901277, https://bugzilla.suse.com/912014, https://bugzilla.suse.com/912015, https://bugzilla.suse.com/912018, https://bugzilla.suse.com/912293, https://bugzilla.suse.com/912294, https://bugzilla.suse.com/912296, https://bugzilla.suse.com/915976, https://bugzilla.suse.com/919648, https://bugzilla.suse.com/920236, https://bugzilla.suse.com/922488, https://bugzilla.suse.com/922496, https://bugzilla.suse.com/922499, https://bugzilla.suse.com/922500, https://bugzilla.suse.com/922501, https://bugzilla.suse.com/929678, https://bugzilla.suse.com/931698, https://bugzilla.suse.com/933911, https://bugzilla.suse.com/934487, https://bugzilla.suse.com/934489, https://bugzilla.suse.com/934491, https://bugzilla.suse.com/934493, https://www.suse.com/security/cve/CVE-2009-5146, https://www.suse.com/security/cve/CVE-2013-0166, https://www.suse.com/security/cve/CVE-2013-0169, https://www.suse.com/security/cve/CVE-2014-0076, https://www.suse.com/security/cve/CVE-2014-0221, https://www.suse.com/security/cve/CVE-2014-0224, https://www.suse.com/security/cve/CVE-2014-3470, https://www.suse.com/security/cve/CVE-2014-3505, https://www.suse.com/security/cve/CVE-2014-3506, https://www.suse.com/security/cve/CVE-2014-3507, https://www.suse.com/security/cve/CVE-2014-3508, https://www.suse.com/security/cve/CVE-2014-3510, https://www.suse.com/security/cve/CVE-2014-3513, https://www.suse.com/security/cve/CVE-2014-3566, https://www.suse.com/security/cve/CVE-2014-3567, https://www.suse.com/security/cve/CVE-2014-3568, https://www.suse.com/security/cve/CVE-2014-3570, https://www.suse.com/security/cve/CVE-2014-3571, https://www.suse.com/security/cve/CVE-2014-3572, https://www.suse.com/security/cve/CVE-2014-8275, https://www.suse.com/security/cve/CVE-2015-0204, https://www.suse.com/security/cve/CVE-2015-0205, https://www.suse.com/security/cve/CVE-2015-0209, https://www.suse.com/security/cve/CVE-2015-0286, https://www.suse.com/security/cve/CVE-2015-0287, https://www.suse.com/security/cve/CVE-2015-0288, https://www.suse.com/security/cve/CVE-2015-0289, https://www.suse.com/security/cve/CVE-2015-0292, https://www.suse.com/security/cve/CVE-2015-0293, https://www.suse.com/security/cve/CVE-2015-1788, https://www.suse.com/security/cve/CVE-2015-1789, https://www.suse.com/security/cve/CVE-2015-1790, https://www.suse.com/security/cve/CVE-2015-1791, https://www.suse.com/security/cve/CVE-2015-1792, https://www.suse.com/security/cve/CVE-2015-3216, https://www.suse.com/security/cve/CVE-2015-4000
