{"affected":[{"ecosystem_specific":{"binaries":[{"libopenssl0_9_8":"0.9.8j-70.2","libopenssl0_9_8-32bit":"0.9.8j-70.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12","name":"compat-openssl098","purl":"pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Desktop%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.8j-70.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libopenssl0_9_8":"0.9.8j-70.2","libopenssl0_9_8-32bit":"0.9.8j-70.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Legacy 12","name":"compat-openssl098","purl":"pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"0.9.8j-70.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThe openssl 0.9.8j compatibility package was updated to fix several security vulnerabilities:\n\nCVE-2014-3570: Bignum squaring (BN_sqr) may produce incorrect results\non some platforms, including x86_64.\n\nCVE-2014-3571: Fix crash in dtls1_get_record whilst in the listen state where\nyou get two separate reads performed - one for the header and\none for the body of the handshake record.\n\nCVE-2014-3572: Do not accept a handshake using an ephemeral ECDH ciphersuites\nwith the server key exchange message omitted.\n\nCVE-2014-8275: Fixed various certificate fingerprint issues\n\nCVE-2015-0204: Only allow ephemeral RSA keys in export ciphersuites\n\nCVE-2015-0205: OpenSSL 0.9.8j is NOT vulnerable to CVE-2015-0205 as it doesn't\nsupport DH certificates and this typo prohibits skipping of\ncertificate verify message for sign only certificates anyway.\n(This patch only fixes the wrong condition)\n\nThis update also fixes regression caused by CVE-2014-0224.patch (bnc#892403)\n","id":"SUSE-SU-2015:0305-1","modified":"2015-02-04T12:44:14Z","published":"2015-02-04T12:44:14Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150305-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/892403"},{"type":"REPORT","url":"https://bugzilla.suse.com/912014"},{"type":"REPORT","url":"https://bugzilla.suse.com/912015"},{"type":"REPORT","url":"https://bugzilla.suse.com/912018"},{"type":"REPORT","url":"https://bugzilla.suse.com/912293"},{"type":"REPORT","url":"https://bugzilla.suse.com/912294"},{"type":"REPORT","url":"https://bugzilla.suse.com/912296"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-0224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-3570"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-3571"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-3572"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-8275"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-0205"}],"related":["CVE-2014-0224","CVE-2014-3570","CVE-2014-3571","CVE-2014-3572","CVE-2014-8275","CVE-2015-0204","CVE-2015-0205"],"summary":"Security update for compat-openssl098","upstream":["CVE-2014-0224","CVE-2014-3570","CVE-2014-3571","CVE-2014-3572","CVE-2014-8275","CVE-2015-0204","CVE-2015-0205"]}