Mailinglist Archive: opensuse-security-announce (65 mails)

< Previous Next >
[security-announce] openSUSE-SU-2017:0792-1: important: Security update for mbedtls
openSUSE Security Update: Security update for mbedtls

Announcement ID: openSUSE-SU-2017:0792-1
Rating: important
References: #1029017
Cross-References: CVE-2017-2784
Affected Products:
SUSE Package Hub for SUSE Linux Enterprise 12

An update that fixes one vulnerability is now available.


This update to mbedtls 1.3.19 fixes security issues and bugs.

The following vulnerability was fixed:

CVE-2017-2784: A remote user could have used a specially crafted
certificate to cause mbedtls to free a buffer allocated on the stack when
verifying the validity
of public key with a secp224k1 curve, which could have
allowed remote code execution on some platforms (boo#1029017)

The following non-security changes are included:

- Add checks to prevent signature forgeries for very large messages while
using RSA through the PK module in 64-bit systems.
- Fixed potential livelock during the parsing of a CRL in PEM format

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2017-372=1

To bring your system up-to-date, use "zypper patch".

Package List:

- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x


- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 x86_64):



To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse-security-announce+help@xxxxxxxxxxxx

< Previous Next >
This Thread
  • No further messages