SUSE-SU-2015:1143-1

Advisory lineage Upstream: 7 Downstream: 0
Published: 17 Jun 2015, 14:42
Last modified:04 Feb 2026, 03:14

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jun 2015, 14:42
Published
Vulnerability first disclosed
04 Feb 2026, 03:14
Last Modified
Vulnerability information updated

Description

Security update for openssl This update of openssl fixes the following security issues: - CVE-2015-4000 (bsc#931698) * The Logjam Attack / weakdh.org * reject connections with DH parameters shorter than 1024 bits * generates 2048-bit DH parameters by default - CVE-2015-1788 (bsc#934487) * Malformed ECParameters causes infinite loop - CVE-2015-1789 (bsc#934489) * Exploitable out-of-bounds read in X509_cmp_time - CVE-2015-1790 (bsc#934491) * PKCS7 crash with missing EnvelopedContent - CVE-2015-1792 (bsc#934493) * CMS verify infinite loop with unknown hash function - CVE-2015-1791 (bsc#933911) * race condition in NewSessionTicket - CVE-2015-3216 (bsc#933898) * Crash in ssleay_rand_bytes due to locking regression - fix a timing side channel in RSA decryption (bnc#929678)

Affected Systems

  • suseopenssl&distro=SUSE Linux Enterprise Desktop 12

    < 1.0.1i-25.1

  • suseopenssl&distro=SUSE Linux Enterprise Server 12

    < 1.0.1i-25.1

  • suseopenssl&distro=SUSE Linux Enterprise Server for SAP Applications 12

    < 1.0.1i-25.1

  • suseopenssl&distro=SUSE Linux Enterprise Software Development Kit 12

    < 1.0.1i-25.1

References (17)