File _patchinfo of Package patchinfo.7982

<patchinfo incident="7982">
  <issue id="1087102" tracker="bnc">VUL-0: CVE-2018-0739: openssl1,openssl,compat-openssl097g,compat-openssl098: Limit ASN.1 constructed types recursive definition depth</issue>
  <issue id="2018-0739" tracker="cve" />
  <category>security</category>
  <rating>moderate</rating>
  <packager>vitezslav_cizek</packager>
  <description>This update for openssl fixes the following issues:

- CVE-2018-0739: Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) 
  could eventually exceed the stack given malicious input with excessive recursion. This could result 
  in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from 
  untrusted sources so this is considered safe. (bsc#1087102).

This update was imported from the SUSE:SLE-12-SP2:Update update project.</description>
  <summary>Security update for openssl</summary>
</patchinfo>
openSUSE Build Service is sponsored by