Описание
Recommended update for mono-core
This update adds handling of SHA256 hashes to parts of the X509 Certificate classes in the C# implementation of Mono (bnc#871362) and improves handling of non-existing certificate revocation lists (bnc#810747, bnc#606002).
Список пакетов
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP3
Ссылки
- Link for SUSE-SU-2015:0841-1
- E-Mail link for SUSE-SU-2015:0841-1
- SUSE Security Ratings
- SUSE Bug 606002
- SUSE Bug 810747
- SUSE Bug 871362
- SUSE Bug 921312
- SUSE CVE CVE-2015-2318 page
- SUSE CVE CVE-2015-2319 page
- SUSE CVE CVE-2015-2320 page
Описание
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
Затронутые продукты
Ссылки
- CVE-2015-2318
- SUSE Bug 921312
Описание
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.
Затронутые продукты
Ссылки
- CVE-2015-2319
- SUSE Bug 921312
Описание
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
Затронутые продукты
Ссылки
- CVE-2015-2320
- SUSE Bug 921312