SuSE: 2014:0762-1: critical: OpenSSL 1.0
Summary
OpenSSL was updated to fix several vulnerabilities:
* SSL/TLS MITM vulnerability. (CVE-2014-0224)
* DTLS recursion flaw. (CVE-2014-0221)
* DTLS invalid fragment vulnerability. (CVE-2014-0195)
* SSL_MODE_RELEASE_BUFFERS NULL pointer dereference. (CVE-2014-0198)
* Anonymous ECDH denial of service. (CVE-2014-3470)
Further information can be found at
References
#876282 #880891
Cross- CVE-2014-0195 CVE-2014-0198 CVE-2014-0221
CVE-2014-0224 CVE-2014-3470
Affected Products:
SUSE Linux Enterprise Security Module 11 SP3
https://www.suse.com/security/cve/CVE-2014-0195.html
https://www.suse.com/security/cve/CVE-2014-0198.html
https://www.suse.com/security/cve/CVE-2014-0221.html
https://www.suse.com/security/cve/CVE-2014-0224.html
https://www.suse.com/security/cve/CVE-2014-3470.html
https://bugzilla.novell.com/876282
https://bugzilla.novell.com/880891
https://scc.suse.com:443/patches/