SUSE-SU-2018:4001-1
Dashboard / Vulnerabilities / SUSE-SU-2018:4001-1
SUSE-SU-2018:4001-1
Summary: Security update for openssl-1_0_0
Details: This update for openssl-1_0_0 fixes the following issues: Security issues fixed: - CVE-2018-0734: Fixed timing vulnerability in DSA signature generation (bsc#1113652). - CVE-2018-5407: Added elliptic curve scalar multiplication timing attack defenses that fixes 'PortSmash' (bsc#1113534). Non-security issues fixed: - Added missing timing side channel patch for DSA signature generation (bsc#1113742). - Set TLS version to 0 in msg_callback for record messages to avoid confusing applications (bsc#1100078). - Fixed infinite loop in DSA generation with incorrect parameters (bsc#1112209)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20184001-1/, https://bugzilla.suse.com/1100078, https://bugzilla.suse.com/1112209, https://bugzilla.suse.com/1113534, https://bugzilla.suse.com/1113652, https://bugzilla.suse.com/1113742, https://www.suse.com/security/cve/CVE-2018-0734, https://www.suse.com/security/cve/CVE-2018-5407
Affected packages
Package
Name: openssl-1_0_0
Purl: pkg:rpm/suse/openssl-1_0_0&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015
Affected ranges
Type: ECOSYSTEM
Events:
