openSUSE Security Update: Security update for mbedtls
Announcement ID: openSUSE-SU-2017:0792-1
SUSE Package Hub for SUSE Linux Enterprise 12
An update that fixes one vulnerability is now available.
This update to mbedtls 1.3.19 fixes security issues and bugs.
The following vulnerability was fixed:
CVE-2017-2784: A remote user could have used a specially crafted
certificate to cause mbedtls to free a buffer allocated on the stack when
verifying the validity
of public key with a secp224k1 curve, which could have
allowed remote code execution on some platforms (boo#1029017)
The following non-security changes are included:
- Add checks to prevent signature forgeries for very large messages while
using RSA through the PK module in 64-bit systems.
- Fixed potential livelock during the parsing of a CRL in PEM format
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE Package Hub for SUSE Linux Enterprise 12:
zypper in -t patch openSUSE-2017-372=1
To bring your system up-to-date, use "zypper patch".
- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64):
- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 x86_64):