{"affected":[{"ecosystem_specific":{"binaries":[{"libopenssl-1_0_0-devel":"1.0.2p-3.11.1","libopenssl1_0_0":"1.0.2p-3.11.1","openssl-1_0_0":"1.0.2p-3.11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Legacy 15","name":"openssl-1_0_0","purl":"pkg:rpm/suse/openssl-1_0_0&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.2p-3.11.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for openssl-1_0_0 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2018-0734: Fixed timing vulnerability in DSA signature generation (bsc#1113652).\n- CVE-2018-5407: Added elliptic curve scalar multiplication timing attack defenses that fixes 'PortSmash' (bsc#1113534).\n\nNon-security issues fixed:\n\n- Added missing timing side channel patch for DSA signature generation (bsc#1113742).\n- Set TLS version to 0 in msg_callback for record messages to avoid confusing applications (bsc#1100078).\n- Fixed infinite loop in DSA generation with incorrect parameters (bsc#1112209)\n","id":"SUSE-SU-2018:4001-1","modified":"2018-12-06T13:33:24Z","published":"2018-12-06T13:33:24Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20184001-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100078"},{"type":"REPORT","url":"https://bugzilla.suse.com/1112209"},{"type":"REPORT","url":"https://bugzilla.suse.com/1113534"},{"type":"REPORT","url":"https://bugzilla.suse.com/1113652"},{"type":"REPORT","url":"https://bugzilla.suse.com/1113742"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-0734"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5407"}],"related":["CVE-2018-0734","CVE-2018-5407"],"summary":"Security update for openssl-1_0_0","upstream":["CVE-2018-0734","CVE-2018-5407"]}