Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2634-1

Опубликовано: 15 сент. 2020
Источник: suse-cvrf

Описание

Security update for compat-openssl098

This update for compat-openssl098 fixes the following issues:

  • CVE-2020-1968: Introduced hardening against the Raccoon attack by always generating fresh DH keys and never reuse them across multiple TLS connections (bsc#1176331).

Список пакетов

Image SLES12-SP4-SAP-Azure
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-EC2-HVM
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-GCE
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-GCE-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-OCI-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-Azure-SAP-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-Azure-SAP-On-Demand
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-EC2-SAP-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-EC2-SAP-On-Demand
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-GCE-SAP-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-GCE-SAP-On-Demand
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libopenssl0_9_8-0.9.8j-106.21.1
SUSE Linux Enterprise Module for Legacy 12
libopenssl0_9_8-0.9.8j-106.21.1
libopenssl0_9_8-32bit-0.9.8j-106.21.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libopenssl0_9_8-0.9.8j-106.21.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libopenssl0_9_8-0.9.8j-106.21.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libopenssl0_9_8-0.9.8j-106.21.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libopenssl0_9_8-0.9.8j-106.21.1

Описание

In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).


Затронутые продукты
Image SLES12-SP4-SAP-Azure-BYOS:libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure:libopenssl0_9_8-0.9.8j-106.21.1

Ссылки

Описание

The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).


Затронутые продукты
Image SLES12-SP4-SAP-Azure-BYOS:libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production:libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production:libopenssl0_9_8-0.9.8j-106.21.1
Image SLES12-SP4-SAP-Azure:libopenssl0_9_8-0.9.8j-106.21.1

Ссылки