SuSE: 2014:1387-1: important: OpenSSL
Summary
This OpenSSL update fixes the following issues:
* Session Ticket Memory Leak (CVE-2014-3567)
* Build option no-ssl3 is incomplete ((CVE-2014-3568)
* Add support for TLS_FALLBACK_SCSV to mitigate CVE-2014-3566 (POODLE)
Security Issues:
* CVE-2014-3567
References
#901223 #901277
Cross- CVE-2014-3566 CVE-2014-3567 CVE-2014-3568
Affected Products:
SUSE Linux Enterprise Server 10 SP4 LTSS
https://www.suse.com/security/cve/CVE-2014-3566.html
https://www.suse.com/security/cve/CVE-2014-3567.html
https://www.suse.com/security/cve/CVE-2014-3568.html
https://bugzilla.suse.com/show_bug.cgi?id=901223
https://bugzilla.suse.com/show_bug.cgi?id=901277
https://scc.suse.com:443/patches/