SUSE-SU-2019:2410-1: moderate: Security update for openssl-1_1
    sle-updates at lists.suse.com 
    sle-updates at lists.suse.com
       
    Fri Sep 20 07:10:50 MDT 2019
    
    
  
   SUSE Security Update: Security update for openssl-1_1
______________________________________________________________________________
Announcement ID:    SUSE-SU-2019:2410-1
Rating:             moderate
References:         #1150003 #1150250 
Cross-References:   CVE-2019-1547 CVE-2019-1563
Affected Products:
                    SUSE Linux Enterprise Module for Open Buildservice Development Tools 15
                    SUSE Linux Enterprise Module for Basesystem 15
______________________________________________________________________________
   An update that fixes two vulnerabilities is now available.
Description:
   This update for openssl-1_1 fixes the following issues:
   OpenSSL Security Advisory [10 September 2019]
   * CVE-2019-1547: Added EC_GROUP_set_generator side channel attack
     avoidance. (bsc#1150003)
   * CVE-2019-1563: Fixed Bleichenbacher attack against cms/pkcs7 encryption
     transported key (bsc#1150250)
Patch Instructions:
   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:
   - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15:
      zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-2410=1
   - SUSE Linux Enterprise Module for Basesystem 15:
      zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-2410=1
Package List:
   - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (noarch):
      openssl-1_1-doc-1.1.0i-4.24.1
   - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (x86_64):
      libopenssl-1_1-devel-32bit-1.1.0i-4.24.1
   - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64):
      libopenssl-1_1-devel-1.1.0i-4.24.1
      libopenssl1_1-1.1.0i-4.24.1
      libopenssl1_1-debuginfo-1.1.0i-4.24.1
      libopenssl1_1-hmac-1.1.0i-4.24.1
      openssl-1_1-1.1.0i-4.24.1
      openssl-1_1-debuginfo-1.1.0i-4.24.1
      openssl-1_1-debugsource-1.1.0i-4.24.1
   - SUSE Linux Enterprise Module for Basesystem 15 (x86_64):
      libopenssl1_1-32bit-1.1.0i-4.24.1
      libopenssl1_1-32bit-debuginfo-1.1.0i-4.24.1
      libopenssl1_1-hmac-32bit-1.1.0i-4.24.1
References:
   https://www.suse.com/security/cve/CVE-2019-1547.html
   https://www.suse.com/security/cve/CVE-2019-1563.html
   https://bugzilla.suse.com/1150003
   https://bugzilla.suse.com/1150250
    
    
More information about the sle-updates
mailing list