Upstream information
Description
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Note from the SUSE Security Team
This option is currently not yet fixed in openssl itself by default, as it would break some clients and servers. So far every openssl using library or program needs to enable the workaround by itself, by removing the SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS from the options passed to the SSL initialization. Novell Bugzilla entries: 716002, 719047, 725167, 726096, 739248, 739256, 742306, 751718, 759666, 814655 SUSE Security Advisories:- SUSE-SU-2012:0114-1, published Mon, 23 Jan 2012 17:08:23 +0100 (CET)
- SUSE-SU-2012:0114-2, published Tue, 6 Mar 2012 21:08:29 +0100 (CET)
- SUSE-SU-2012:0122-1, published Thu, 26 Jan 2012 04:08:11 +0100 (CET)
- SUSE-SU-2012:0122-2, published Thu, 23 Feb 2012 22:08:13 +0100 (CET)
- SUSE-SU-2012:0602-1, published Wed, 9 May 2012 20:08:14 +0200 (CEST)
- openSUSE-SU-2011:1025-1, published Thu, 8 Sep 2011 17:08:15 +0200 (CEST)
- openSUSE-SU-2011:1196-1, published Fri, 28 Oct 2011 17:08:26 +0200 (CEST)
- openSUSE-SU-2012:0030-1, published Thu, 5 Jan 2012 12:09:23 +0100 (CET)
- openSUSE-SU-2012:0063-1, published Thu, 5 Jan 2012 12:36:49 +0100 (CET)
- openSUSE-SU-2012:0229-1, published Thu, 9 Feb 2012 19:10:39 +0100 (CET)
- openSUSE-SU-2012:0667-1, published Wed, 30 May 2012 16:10:15 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Server 10 SP4 for x86 |
| sles10-sp4.ia64 sles10-sp4.s390x sles10-sp4.x86 sles10-sp4.x86-64 sles10-sp4.ppc ZYPP Patch Nr: 7908 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| sles10-sp4.ia64 sles10-sp4.s390x sles10-sp4.x86 sles10-sp4.x86-64 sles10-sp4.ppc ZYPP Patch Nr: 7908 |
| SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit SUSE Linux Enterprise Server 10 SP4 for IPF |
| sles10-sp4.ia64 sles10-sp4.s390x sles10-sp4.x86 sles10-sp4.x86-64 sles10-sp4.ppc ZYPP Patch Nr: 7908 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sles11-sp1-vmware.x86-64 sles11-sp2.ppc sle11-sp1-sdk.ppc sle11-sp2-sdk.x86-64 sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp2.s390x sles11-sp2.x86 sle11-sp2-sdk.ppc sles11-sp2.x86-64 sles11-sp1.x86-64 sles11-sp1.s390x sles11-sp1.ppc sles11-sp1-vmware.x86-64 sle11-sp2-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.x86 sles11-sp1.ppc sle11-sp2-sdk.x86 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1-vmware.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.s390x sle11-sp1-sdk.x86-64 SAT Patch Nr: 5872 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sles11-sp1-vmware.x86-64 sles11-sp2.ppc sle11-sp1-sdk.ppc sle11-sp2-sdk.x86-64 sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp2.s390x sles11-sp2.x86 sle11-sp2-sdk.ppc sles11-sp2.x86-64 sles11-sp1.x86-64 sles11-sp1.s390x sles11-sp1.ppc sles11-sp1-vmware.x86-64 sle11-sp2-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.x86 sles11-sp1.ppc sle11-sp2-sdk.x86 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1-vmware.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.s390x sle11-sp1-sdk.x86-64 SAT Patch Nr: 5872 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware SUSE Linux Enterprise Server 11 SP2 |
| sles11-sp1-vmware.x86-64 sles11-sp2.ppc sle11-sp1-sdk.ppc sle11-sp2-sdk.x86-64 sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp2.s390x sles11-sp2.x86 sle11-sp2-sdk.ppc sles11-sp2.x86-64 sles11-sp1.x86-64 sles11-sp1.s390x sles11-sp1.ppc sles11-sp1-vmware.x86-64 sle11-sp2-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.x86 sles11-sp1.ppc sle11-sp2-sdk.x86 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1-vmware.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.s390x sle11-sp1-sdk.x86-64 SAT Patch Nr: 5872 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP2 |
| sles11-sp1-vmware.x86-64 sles11-sp2.ppc sle11-sp1-sdk.ppc sle11-sp2-sdk.x86-64 sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp2.s390x sles11-sp2.x86 sle11-sp2-sdk.ppc sles11-sp2.x86-64 sles11-sp1.x86-64 sles11-sp1.s390x sles11-sp1.ppc sles11-sp1-vmware.x86-64 sle11-sp2-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.x86 sles11-sp1.ppc sle11-sp2-sdk.x86 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1-vmware.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.s390x sle11-sp1-sdk.x86-64 SAT Patch Nr: 5872 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware SUSE Linux Enterprise Server 11 SP2 |
| sles11-sp1-vmware.x86-64 sles11-sp2.ppc sle11-sp1-sdk.ppc sle11-sp2-sdk.x86-64 sles11-sp1.x86-64 sles11-sp1-vmware.x86 sles11-sp1.x86 sles11-sp1.s390x sle11-sp1-sdk.x86-64 sles11-sp2.s390x sles11-sp2.x86 sle11-sp2-sdk.ppc sles11-sp2.x86-64 sles11-sp1.x86-64 sles11-sp1.s390x sles11-sp1.ppc sles11-sp1-vmware.x86-64 sle11-sp2-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.x86 sles11-sp1.ppc sle11-sp2-sdk.x86 sles11-sp1.x86 sle11-sp1-sdk.x86 sles11-sp1-vmware.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.s390x sle11-sp1-sdk.x86-64 SAT Patch Nr: 5872 |
| SUSE Linux Enterprise Desktop 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 8100 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8100 |
| SUSE Linux Enterprise Server 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 8100 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| Builds ZYPP Patch Nr: 8100 |
| SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit |
| Builds ZYPP Patch Nr: 8100 |
| SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8100 |
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 |
| |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sles11-sp1.ppc sle11-sp2-sdk.x86 sle11-sp1-sdk.ia64 sles11-sp2.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sles11-sp2.ppc sles11-sp2.ia64 sle11-sp1-sdk.s390x sle11-sp2-sdk.s390x sles11-sp1.ia64 sle11-sp2-sdk.x86-64 sles11-sp1.x86 sles11-sp1.s390x sles11-sp2.s390x sle11-sp2-sdk.ia64 sles11-sp1-vmware.x86-64 sles11-sp1-vmware.x86-64 sles11-sp2.x86 sle11-sp1-sdk.ia64 sles11-sp1-vmware.x86 sle11-sp2-sdk.ppc sle11-sp1-sdk.x86 sle11-sp1-sdk.ppc sles11-sp1.ia64 SAT Patch Nr: 5609 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sles11-sp1.ppc sle11-sp2-sdk.x86 sle11-sp1-sdk.ia64 sles11-sp2.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sles11-sp2.ppc sles11-sp2.ia64 sle11-sp1-sdk.s390x sle11-sp2-sdk.s390x sles11-sp1.ia64 sle11-sp2-sdk.x86-64 sles11-sp1.x86 sles11-sp1.s390x sles11-sp2.s390x sle11-sp2-sdk.ia64 sles11-sp1-vmware.x86-64 sles11-sp1-vmware.x86-64 sles11-sp2.x86 sle11-sp1-sdk.ia64 sles11-sp1-vmware.x86 sle11-sp2-sdk.ppc sle11-sp1-sdk.x86 sle11-sp1-sdk.ppc sles11-sp1.ia64 SAT Patch Nr: 5609 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1.ppc sle11-sp2-sdk.x86 sle11-sp1-sdk.ia64 sles11-sp2.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sles11-sp2.ppc sles11-sp2.ia64 sle11-sp1-sdk.s390x sle11-sp2-sdk.s390x sles11-sp1.ia64 sle11-sp2-sdk.x86-64 sles11-sp1.x86 sles11-sp1.s390x sles11-sp2.s390x sle11-sp2-sdk.ia64 sles11-sp1-vmware.x86-64 sles11-sp1-vmware.x86-64 sles11-sp2.x86 sle11-sp1-sdk.ia64 sles11-sp1-vmware.x86 sle11-sp2-sdk.ppc sle11-sp1-sdk.x86 sle11-sp1-sdk.ppc sles11-sp1.ia64 SAT Patch Nr: 5609 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware |
| sles11-sp1.ppc sle11-sp2-sdk.x86 sle11-sp1-sdk.ia64 sles11-sp2.x86-64 sles11-sp1.x86-64 sle11-sp1-sdk.x86-64 sles11-sp2.ppc sles11-sp2.ia64 sle11-sp1-sdk.s390x sle11-sp2-sdk.s390x sles11-sp1.ia64 sle11-sp2-sdk.x86-64 sles11-sp1.x86 sles11-sp1.s390x sles11-sp2.s390x sle11-sp2-sdk.ia64 sles11-sp1-vmware.x86-64 sles11-sp1-vmware.x86-64 sles11-sp2.x86 sle11-sp1-sdk.ia64 sles11-sp1-vmware.x86 sle11-sp2-sdk.ppc sle11-sp1-sdk.x86 sle11-sp1-sdk.ppc sles11-sp1.ia64 SAT Patch Nr: 5609 |
| SUSE Linux Enterprise Desktop 10 SP4 for x86 SUSE Linux Enterprise Server 10 SP4 for x86 |
| sled10-sp4.x86-64 sles10-sp4.ia64 sle10-sp4-sdk.x86-64 sle10-sp4-sdk.x86 sle10-sp4-sdk.ia64 sles10-sp4.ppc sles10-sp4.x86-64 sles10-sp4.x86 sled10-sp4.x86 sle10-sp4-sdk.ppc sle10-sp4-sdk.s390x sles10-sp4.s390x ZYPP Patch Nr: 7937 |
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries SLE SDK 10 SP4 for IBM zSeries SLE SDK 10 SP4 for IPF SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 |
| sled10-sp4.x86-64 sles10-sp4.ia64 sle10-sp4-sdk.x86-64 sle10-sp4-sdk.x86 sle10-sp4-sdk.ia64 sles10-sp4.ppc sles10-sp4.x86-64 sles10-sp4.x86 sled10-sp4.x86 sle10-sp4-sdk.ppc sle10-sp4-sdk.s390x sles10-sp4.s390x ZYPP Patch Nr: 7937 |
| SUSE Linux Enterprise Server 10 SP4 for IPF |
| sled10-sp4.x86-64 sles10-sp4.ia64 sle10-sp4-sdk.x86-64 sle10-sp4-sdk.x86 sle10-sp4-sdk.ia64 sles10-sp4.ppc sles10-sp4.x86-64 sles10-sp4.x86 sled10-sp4.x86 sle10-sp4-sdk.ppc sle10-sp4-sdk.s390x sles10-sp4.s390x ZYPP Patch Nr: 7937 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| sled10-sp4.x86-64 sles10-sp4.ia64 sle10-sp4-sdk.x86-64 sle10-sp4-sdk.x86 sle10-sp4-sdk.ia64 sles10-sp4.ppc sles10-sp4.x86-64 sles10-sp4.x86 sled10-sp4.x86 sle10-sp4-sdk.ppc sle10-sp4-sdk.s390x sles10-sp4.s390x ZYPP Patch Nr: 7937 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit |
| sled10-sp4.x86-64 sles10-sp4.ia64 sle10-sp4-sdk.x86-64 sle10-sp4-sdk.x86 sle10-sp4-sdk.ia64 sles10-sp4.ppc sles10-sp4.x86-64 sles10-sp4.x86 sled10-sp4.x86 sle10-sp4-sdk.ppc sle10-sp4-sdk.s390x sles10-sp4.s390x ZYPP Patch Nr: 7937 |
| SUSE Linux Enterprise Desktop 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 8080 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T |
| Builds ZYPP Patch Nr: 8080 |
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries SLE SDK 10 SP4 for IBM zSeries SLE SDK 10 SP4 for IPF SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 8080 |
| SUSE Linux Enterprise Server 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 8080 |
| SUSE Linux Enterprise Server 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 8080 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| Builds ZYPP Patch Nr: 8080 |
| SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit |
| Builds ZYPP Patch Nr: 8080 |
| SUSE CORE 9 for AMD64 and Intel EM64T |
| Builds YOU Patch Nr: 12858 |
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.3 |
| |
| openSUSE 11.4 |
| |
| SUSE Linux Enterprise for SAP Applications 11 SP1 |
| Builds SAT Patch Nr: 5734 |
| SUSE Linux Enterprise Desktop 10 SP4 for x86 SUSE Linux Enterprise Server 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 7842 |
| SLE SDK 10 SP4 for IBM iSeries and IBM pSeries SLE SDK 10 SP4 for IBM zSeries SLE SDK 10 SP4 for IPF SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IPF |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| Builds ZYPP Patch Nr: 7842 |
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit |
| Builds ZYPP Patch Nr: 7842 |
| openSUSE 11.3 openSUSE 11.4 |
| |
| openSUSE 11.3 openSUSE 11.4 DEBUGINFO |
| |
| SUSE Linux Enterprise Server 10 SP4 for x86 |
| sles10-sp4.ppc sles10-sp4.s390x sles10-sp4.x86-64 sles10-sp4.x86 ZYPP Patch Nr: 7926 |
| SUSE Linux Enterprise Server 10 SP4 for IBM POWER |
| sles10-sp4.ppc sles10-sp4.s390x sles10-sp4.x86-64 sles10-sp4.x86 ZYPP Patch Nr: 7926 |
| SUSE Linux Enterprise Server 10 SP4 for IBM zSeries 64bit |
| sles10-sp4.ppc sles10-sp4.s390x sles10-sp4.x86-64 sles10-sp4.x86 ZYPP Patch Nr: 7926 |
| SUSE Linux Enterprise Server 10 SP4 for AMD64 and Intel EM64T |
| sles10-sp4.ppc sles10-sp4.s390x sles10-sp4.x86-64 sles10-sp4.x86 ZYPP Patch Nr: 7926 |
| SUSE CORE 9 for AMD64 and Intel EM64T |
| Builds YOU Patch Nr: 12855 |
