SuSE: 2015:0578-1: important: compat-openssl097g
Summary
OpenSSL has been updated to fix various security issues: * CVE-2014-3568: The build option no-ssl3 was incomplete. * CVE-2014-3566: Support for TLS_FALLBACK_SCSV was added. * CVE-2014-3508: An information leak in pretty printing functions was fixed. * CVE-2013-0166: A OCSP bad key DoS attack was fixed. * CVE-2013-0169: An SSL/TLS CBC plaintext recovery attack was fixed. * CVE-2014-3470: Anonymous ECDH denial of service was fixed. * CVE-2014-0224: A SSL/TLS MITM vulnerability was fixed. * CVE-2014-3570: Bignum squaring (BN_sqr) may have produced incorrect results on some platforms, including x86_64. * CVE-2014-3572: Don't accept a handshake using an ephemeral ECDH ciphersuites with the server key exchange message omitted. * CVE-2014-8275: Fixed various certificate fingerprint issues. * ...
Read the Full AdvisoryReferences
#802184 #880891 #890764 #901223 #901277 #905106
#912014 #912015 #912018 #912293 #912296 #920236
#922488 #922496 #922499 #922500 #922501
Affected Products:
SUSE Linux Enterprise for SAP Applications 11 SP2
https://bugzilla.suse.com/802184
https://bugzilla.suse.com/880891
https://bugzilla.suse.com/890764
https://bugzilla.suse.com/901223
https://bugzilla.suse.com/901277
https://bugzilla.suse.com/905106
https://bugzilla.suse.com/912014
https://bugzilla.suse.com/912015
https://bugzilla.suse.com/912018
https://bugzilla.suse.com/912293
https://bugzilla.suse.com/912296
https://bugzilla.suse.com/920236
https://bugzilla.suse.com/922488
https://bugzilla.suse.com/922496
https://bugzilla.suse.com/922499
https://bugzilla.suse.com/922500
https://bugzilla.suse.com/922501
https://scc.suse.com:443/patches/