SuSE: 2014:1386-1: important: OpenSSL
Summary
This OpenSSL update fixes the following issues:
* Session Ticket Memory Leak (CVE-2014-3567)
* Build option no-ssl3 is incomplete ((CVE-2014-3568)
* Add support for TLS_FALLBACK_SCSV to mitigate CVE-2014-3566 (POODLE)
Security Issues:
* CVE-2014-3513
References
#892403 #901223 #901277
Cross- CVE-2014-3513 CVE-2014-3566 CVE-2014-3567
CVE-2014-3568
Affected Products:
SUSE Linux Enterprise Server 11 SP2 LTSS
SUSE Linux Enterprise Server 11 SP1 LTSS
https://www.suse.com/security/cve/CVE-2014-3513.html
https://www.suse.com/security/cve/CVE-2014-3566.html
https://www.suse.com/security/cve/CVE-2014-3567.html
https://www.suse.com/security/cve/CVE-2014-3568.html
https://bugzilla.suse.com/show_bug.cgi?id=892403
https://bugzilla.suse.com/show_bug.cgi?id=901223
https://bugzilla.suse.com/show_bug.cgi?id=901277
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/