File _patchinfo of Package patchinfo.7855
<patchinfo incident="7855">
<issue id="1097158" tracker="bnc">VUL-0: CVE-2018-0732: openssl1,openssl,compat-openssl098: Reject excessively large primes in DH key generation.</issue>
<issue id="1097624" tracker="bnc">VUL-1: openssl,openssl1,openssl-1_1,openssl-1_0_2: blinding enhancements for ECDSA</issue>
<issue id="1098592" tracker="bnc">VUL-1: openssl,openssl1,openssl-1_1,openssl-1_0_2: blinding enhancements for DSA</issue>
<issue id="2018-0732" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>simotek</packager>
<description>This update for openssl-1_1 fixes the following issues:
- CVE-2018-0732: During key agreement in a TLS handshake using a DH(E) based
ciphersuite a malicious server could have sent a very large prime value to the
client. This caused the client to spend an unreasonably long period of time
generating a key for this prime resulting in a hang until the client has
finished. This could be exploited in a Denial Of Service attack (bsc#1097158).
- Blinding enhancements for ECDSA and DSA (bsc#1097624, bsc#1098592)
</description>
<summary>Security update for openssl-1_1</summary>
</patchinfo>