Bug 922503 (CVE-2015-1787) - VUL-1: CVE-2015-1787: openssl: [1.0.2 only] Empty CKE with client auth and DHE
Summary: VUL-1: CVE-2015-1787: openssl: [1.0.2 only] Empty CKE with client auth and DHE
Status: RESOLVED UPSTREAM
Alias: CVE-2015-1787
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-03-16 11:02 UTC by Marcus Meissner
Modified: 2015-03-19 14:14 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Vítězslav Čížek 2015-03-16 13:03:04 UTC
We don't ship openssl 1.0.2. (Factory has 1.0.1k)
Comment 2 Swamp Workflow Management 2015-03-16 23:02:13 UTC
bugbot adjusting priority
Comment 4 Marcus Meissner 2015-03-19 14:14:13 UTC
http://openssl.org/news/secadv_20150319.txt

Empty CKE with client auth and DHE (CVE-2015-1787)
==================================================

Severity: Moderate

If client auth is used then a server can seg fault in the event of a DHE
ciphersuite being selected and a zero length ClientKeyExchange message being
sent by the client. This could be exploited in a DoS attack.

This issue affects OpenSSL version: 1.0.2

OpenSSL 1.0.2 users should upgrade to 1.0.2a.

This issue was discovered and the fix was developed by Matt Caswell of the
OpenSSL development team.
Comment 5 Marcus Meissner 2015-03-19 14:14:34 UTC
we did not ship 1.0.2 yet, so are not affected.