Security update for haproxy

Announcement ID: SUSE-SU-2015:1663-1
Rating: important
References:
Cross-References:
CVSS scores:
  • CVE-2015-4000 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products:
  • SUSE Cloud for SLE 12 Compute Nodes 5
  • SUSE Linux Enterprise High Availability Extension 12
  • SUSE Linux Enterprise Server 12
  • SUSE Linux Enterprise Server for SAP Applications 12

An update that solves two vulnerabilities can now be installed.

Description:

haproxy was updated to fix two security issues.

These security issues were fixed: - CVE-2015-3281: Information disclosure (bsc#937042). - CVE-2015-4000: The Logjam Attack / weakdh.org (bsc#937202).

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Cloud for SLE 12 Compute Nodes 5
    zypper in -t patch SUSE-SLE12-CLOUD-5-2015-625=1
  • SUSE Linux Enterprise High Availability Extension 12
    zypper in -t patch SUSE-SLE-HA-12-2015-625=1
  • SUSE Linux Enterprise Server for SAP Applications 12
    zypper in -t patch SUSE-SLE-HA-12-2015-625=1

Package List:

  • SUSE Cloud for SLE 12 Compute Nodes 5 (x86_64)
    • haproxy-debuginfo-1.5.4-2.4.1
    • haproxy-debugsource-1.5.4-2.4.1
    • haproxy-1.5.4-2.4.1
  • SUSE Linux Enterprise High Availability Extension 12 (s390x x86_64)
    • haproxy-debuginfo-1.5.4-2.4.1
    • haproxy-debugsource-1.5.4-2.4.1
    • haproxy-1.5.4-2.4.1
  • SUSE Linux Enterprise Server for SAP Applications 12 (x86_64)
    • haproxy-debuginfo-1.5.4-2.4.1
    • haproxy-debugsource-1.5.4-2.4.1
    • haproxy-1.5.4-2.4.1

References: