SuSE: 2014:0761-1: critical: OpenSSL
Summary
OpenSSL was updated to fix several vulnerabilities:
* SSL/TLS MITM vulnerability. (CVE-2014-0224)
* DTLS recursion flaw. (CVE-2014-0221)
* Anonymous ECDH denial of service. (CVE-2014-3470)
* Using the FLUSH+RELOAD Cache Side-channel Attack the nonces could
have been recovered. (CVE-2014-0076)
Further information can be found at
References
#859228 #859924 #860332 #862181 #869945 #870192
#880891
Cross- CVE-2014-0076 CVE-2014-0221 CVE-2014-0224
CVE-2014-3470
Affected Products:
SUSE Linux Enterprise Server 11 SP2 LTSS
SUSE Linux Enterprise Server 11 SP1 LTSS
https://www.suse.com/security/cve/CVE-2014-0076.html
https://www.suse.com/security/cve/CVE-2014-0221.html
https://www.suse.com/security/cve/CVE-2014-0224.html
https://www.suse.com/security/cve/CVE-2014-3470.html
https://bugzilla.novell.com/859228
https://bugzilla.novell.com/859924
https://bugzilla.novell.com/860332
https://bugzilla.novell.com/862181
https://bugzilla.novell.com/869945
https://bugzilla.novell.com/870192
https://bugzilla.novell.com/880891
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/