File _patchinfo of Package patchinfo.7855

<patchinfo incident="7855">
  <issue id="1097158" tracker="bnc">VUL-0: CVE-2018-0732: openssl1,openssl,compat-openssl098: Reject excessively large primes in DH key generation.</issue>
  <issue id="1097624" tracker="bnc">VUL-1: openssl,openssl1,openssl-1_1,openssl-1_0_2: blinding enhancements for ECDSA</issue>
  <issue id="1098592" tracker="bnc">VUL-1: openssl,openssl1,openssl-1_1,openssl-1_0_2: blinding enhancements for DSA</issue>
  <issue id="2018-0732" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>simotek</packager>
  <description>This update for openssl-1_1 fixes the following issues:

- CVE-2018-0732: During key agreement in a TLS handshake using a DH(E) based
  ciphersuite a malicious server could have sent a very large prime value to the
  client. This caused the client to spend an unreasonably long period of time
  generating a key for this prime resulting in a hang until the client has
  finished. This could be exploited in a Denial Of Service attack (bsc#1097158).
- Blinding enhancements for ECDSA and DSA (bsc#1097624, bsc#1098592)
</description>
  <summary>Security update for openssl-1_1</summary>
</patchinfo>

openSUSE Build Service is sponsored by