SUSE-SU-2018:3864-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3864-1
SUSE-SU-2018:3864-1
Summary: Security update for openssl
Details: This update for openssl fixes the following issues: Security issues fixed: - CVE-2018-0734: Fixed timing vulnerability in DSA signature generation (bsc#1113652). - CVE-2018-5407: Fixed elliptic curve scalar multiplication timing attack defenses (bsc#1113534). - CVE-2018-0737: Corrected the current error detection of the current fix (bsc#1106197). - CVE-2016-8610: Adjusted current fix and add missing error string (bsc#1110018). - Add missing timing side channel patch for DSA signature generation (bsc#1113742). - Fixed the 'One and Done' side-channel attack on RSA (bsc#1104789). Non-security issues fixed: - Added openssl(cli) so that the packages that required the openssl binary can require this instead of the new openssl meta package (bsc#1101470).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183864-1/, https://bugzilla.suse.com/1101470, https://bugzilla.suse.com/1104789, https://bugzilla.suse.com/1106197, https://bugzilla.suse.com/1110018, https://bugzilla.suse.com/1113534, https://bugzilla.suse.com/1113652, https://www.suse.com/security/cve/CVE-2016-8610, https://www.suse.com/security/cve/CVE-2018-0734, https://www.suse.com/security/cve/CVE-2018-0737, https://www.suse.com/security/cve/CVE-2018-5407
Affected packages
Package
Name: openssl
Purl: pkg:rpm/suse/openssl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS
Affected ranges
Type: ECOSYSTEM
Events:
