Security update for OpenSSL

SUSE Security Update: Security update for OpenSSL
Announcement ID: SUSE-SU-2014:0539-1
Rating: moderate
References: #866916 #869945
Affected Products:
  • SUSE Linux Enterprise Server 10 SP3 LTSS

  • An update that solves one vulnerability and has one errata is now available.

    Description:


    OpenSSL has been updated to fix an attack on ECDSA Nonces.

    Using the FLUSH+RELOAD Cache Side-channel Attack the Nonces
    could be recovered. (CVE-2014-0076)

    The update also enables use of SHA-2 family certificate
    verification of X.509 certificates used in todays SSL
    certificate infrastructure.

    Security Issue reference:

    * CVE-2014-0076
    >

    Package List:

    • SUSE Linux Enterprise Server 10 SP3 LTSS (i586 s390x x86_64):
    • openssl-0.9.8a-18.45.75.1
    • openssl-devel-0.9.8a-18.45.75.1
    • openssl-doc-0.9.8a-18.45.75.1
    • SUSE Linux Enterprise Server 10 SP3 LTSS (s390x x86_64):
    • openssl-32bit-0.9.8a-18.45.75.1
    • openssl-devel-32bit-0.9.8a-18.45.75.1

    References:

    • http://support.novell.com/security/cve/CVE-2014-0076.html
    • https://bugzilla.novell.com/866916
    • https://bugzilla.novell.com/869945
    • http://download.suse.com/patch/finder/?keywords=5e45bbc40560ab190992f4af60dbbccc