VYPR

rpm package

suse/compat-openssl098&distro=SUSE Linux Enterprise Module for Legacy 12

pkg:rpm/suse/compat-openssl098&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012

Vulnerabilities (67)

  • CVE-2015-0205Jan 9, 2015
    affected < 0.9.8j-70.2fixed 0.9.8j-70.2

    The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowled

  • CVE-2015-0204Jan 9, 2015
    affected < 0.9.8j-70.2fixed 0.9.8j-70.2

    The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncomp

  • CVE-2014-8275Jan 9, 2015
    affected < 0.9.8j-70.2fixed 0.9.8j-70.2

    OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's u

  • CVE-2014-3572Jan 9, 2015
    affected < 0.9.8j-70.2fixed 0.9.8j-70.2

    The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.

  • CVE-2014-3571Jan 9, 2015
    affected < 0.9.8j-70.2fixed 0.9.8j-70.2

    OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message that is processed with a different read operation for the handshake header than fo

  • CVE-2014-3570Jan 9, 2015
    affected < 0.9.8j-70.2fixed 0.9.8j-70.2

    The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, relat

  • CVE-2014-0224HigJun 5, 2014
    affected < 0.9.8j-70.2fixed 0.9.8j-70.2

    OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequen

Page 4 of 4