Bugzilla – Bug 890772
VUL-0: CVE-2014-3512: openssl: SRP buffer overrun
Last modified: 2014-09-11 07:36:21 UTC
This CVE was part of the OpenSSL Security Advisory [6 Aug 2014] (bnc#Bug 890759). SRP buffer overrun (CVE-2014-3512) ================================== A malicious client or server can send invalid SRP parameters and overrun an internal buffer. Only applications which are explicitly set up for SRP use are affected. OpenSSL 1.0.1 SSL/TLS users should upgrade to 1.0.1i. Thanks to Sean Devlin and Watson Ladd (Cryptography Services, NCC Group) for discovering this issue. This issue was reported to OpenSSL on 31st July 2014. The fix was developed by Stephen Henson of the OpenSSL core team.
Created attachment 601530 [details] CVE-2014-3512 fix for the 1.0.1 branch.
bugbot adjusting priority
Affected packages: SLE-10-SP3-TERADATA: openssl SLE-11-SP1: openssl SLE-11-SP3: openssl, openssl1
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2014-08-22. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/58532
All packages have been submitted. Reassigning back to security-team.
openSUSE-SU-2014:1052-1: An update that fixes 9 vulnerabilities is now available. Category: security (moderate) Bug References: 890764,890765,890766,890767,890768,890769,890770,890771,890772 CVE References: CVE-2014-3505,CVE-2014-3506,CVE-2014-3507,CVE-2014-3508,CVE-2014-3509,CVE-2014-3510,CVE-2014-3511,CVE-2014-3512,CVE-2014-5139 Sources used: openSUSE 13.1 (src): openssl-1.0.1i-11.52.1 openSUSE 12.3 (src): openssl-1.0.1i-1.64.1
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2014-09-11. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/58762
released