<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for openssl-1_1</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2019:0678-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-03-21T09:40:36Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-03-21T09:40:36Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-03-21T09:40:36Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for openssl-1_1</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for openssl-1_1 (OpenSSL Security Advisory [6 March 2019]) fixes the following issues:

Security issue fixed: 	  

- CVE-2019-1543: Fixed an implementation error in ChaCha20-Poly1305 where it was allowed
  to set IV with more than 12 bytes (bsc#1128189).
  
Other issues addressed:   

- Fixed a segfault in openssl speed when an unknown algorithm is passed (bsc#1125494).
- Correctly skipped binary curves in openssl speed to avoid spitting errors (bsc#1116833).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Container suse/sle15:15.0-2019-678,Image SLES15-Azure-BYOS-2019-678,Image SLES15-EC2-CHOST-HVM-BYOS-2019-678,Image SLES15-EC2-HVM-BYOS-2019-678,Image SLES15-GCE-BYOS-2019-678,Image SLES15-OCI-BYOS-2019-678,Image SLES15-SAP-Azure-2019-678,Image SLES15-SAP-Azure-BYOS-2019-678,Image SLES15-SAP-Azure-LI-BYOS-Production-2019-678,Image SLES15-SAP-Azure-VLI-BYOS-Production-2019-678,Image SLES15-SAP-EC2-HVM-2019-678,Image SLES15-SAP-EC2-HVM-BYOS-2019-678,Image SLES15-SAP-GCE-2019-678,Image SLES15-SAP-GCE-BYOS-2019-678,Image SLES15-SAP-OCI-BYOS-2019-678,SUSE-2019-678,SUSE-SLE-Module-Basesystem-15-2019-678,SUSE-SLE-Module-Development-Tools-OBS-15-2019-678</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20190678-1/</URL>
      <Description>Link for SUSE-SU-2019:0678-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2019-March/005214.html</URL>
      <Description>E-Mail link for SUSE-SU-2019:0678-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1116833</URL>
      <Description>SUSE Bug 1116833</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1125494</URL>
      <Description>SUSE Bug 1125494</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128189</URL>
      <Description>SUSE Bug 1128189</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1543/</URL>
      <Description>SUSE CVE CVE-2019-1543 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Container suse/sle15:15.0">
      <Branch Type="Product Name" Name="Container suse/sle15:15.0">
        <FullProductName ProductID="Container suse/sle15:15.0">Container suse/sle15:15.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-Azure-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-Azure-BYOS">
        <FullProductName ProductID="Image SLES15-Azure-BYOS">Image SLES15-Azure-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-EC2-CHOST-HVM-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-EC2-CHOST-HVM-BYOS">
        <FullProductName ProductID="Image SLES15-EC2-CHOST-HVM-BYOS">Image SLES15-EC2-CHOST-HVM-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-EC2-HVM-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-EC2-HVM-BYOS">
        <FullProductName ProductID="Image SLES15-EC2-HVM-BYOS">Image SLES15-EC2-HVM-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-GCE-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-GCE-BYOS">
        <FullProductName ProductID="Image SLES15-GCE-BYOS">Image SLES15-GCE-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-OCI-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-OCI-BYOS">
        <FullProductName ProductID="Image SLES15-OCI-BYOS">Image SLES15-OCI-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SAP-Azure">
        <FullProductName ProductID="Image SLES15-SAP-Azure">Image SLES15-SAP-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-Azure-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SAP-Azure-BYOS">
        <FullProductName ProductID="Image SLES15-SAP-Azure-BYOS">Image SLES15-SAP-Azure-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SAP-Azure-LI-BYOS-Production">Image SLES15-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SAP-Azure-VLI-BYOS-Production">Image SLES15-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SAP-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SAP-EC2-HVM">Image SLES15-SAP-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-EC2-HVM-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SAP-EC2-HVM-BYOS">
        <FullProductName ProductID="Image SLES15-SAP-EC2-HVM-BYOS">Image SLES15-SAP-EC2-HVM-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SAP-GCE">
        <FullProductName ProductID="Image SLES15-SAP-GCE">Image SLES15-SAP-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-GCE-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SAP-GCE-BYOS">
        <FullProductName ProductID="Image SLES15-SAP-GCE-BYOS">Image SLES15-SAP-GCE-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SAP-OCI-BYOS">
      <Branch Type="Product Name" Name="Image SLES15-SAP-OCI-BYOS">
        <FullProductName ProductID="Image SLES15-SAP-OCI-BYOS">Image SLES15-SAP-OCI-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Basesystem 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15" CPE="cpe:/o:suse:sle-module-basesystem:15">SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl1_1-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openssl-1_1-1.1.0i-4.21.1">
      <FullProductName ProductID="openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl-1_1-devel-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl-1_1-devel-1.1.0i-4.21.1">libopenssl-1_1-devel-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl-1_1-devel-32bit-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl-1_1-devel-32bit-1.1.0i-4.21.1">libopenssl-1_1-devel-32bit-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl-1_1-devel-64bit-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl-1_1-devel-64bit-1.1.0i-4.21.1">libopenssl-1_1-devel-64bit-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl1_1-32bit-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl1_1-32bit-1.1.0i-4.21.1">libopenssl1_1-32bit-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl1_1-64bit-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl1_1-64bit-1.1.0i-4.21.1">libopenssl1_1-64bit-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl1_1-hmac-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl1_1-hmac-1.1.0i-4.21.1">libopenssl1_1-hmac-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl1_1-hmac-32bit-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl1_1-hmac-32bit-1.1.0i-4.21.1">libopenssl1_1-hmac-32bit-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl1_1-hmac-64bit-1.1.0i-4.21.1">
      <FullProductName ProductID="libopenssl1_1-hmac-64bit-1.1.0i-4.21.1">libopenssl1_1-hmac-64bit-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openssl-1_1-doc-1.1.0i-4.21.1">
      <FullProductName ProductID="openssl-1_1-doc-1.1.0i-4.21.1">openssl-1_1-doc-1.1.0i-4.21.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle15:15.0">
      <FullProductName ProductID="Container suse/sle15:15.0:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Container suse/sle15:15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/sle15:15.0">
      <FullProductName ProductID="Container suse/sle15:15.0:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Container suse/sle15:15.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-Azure-BYOS">
      <FullProductName ProductID="Image SLES15-Azure-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-Azure-BYOS">
      <FullProductName ProductID="Image SLES15-Azure-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-EC2-CHOST-HVM-BYOS">
      <FullProductName ProductID="Image SLES15-EC2-CHOST-HVM-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-EC2-CHOST-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-EC2-CHOST-HVM-BYOS">
      <FullProductName ProductID="Image SLES15-EC2-CHOST-HVM-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-EC2-CHOST-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES15-EC2-HVM-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES15-EC2-HVM-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-GCE-BYOS">
      <FullProductName ProductID="Image SLES15-GCE-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-GCE-BYOS">
      <FullProductName ProductID="Image SLES15-GCE-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-OCI-BYOS">
      <FullProductName ProductID="Image SLES15-OCI-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-OCI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-OCI-BYOS">
      <FullProductName ProductID="Image SLES15-OCI-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-OCI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure">
      <FullProductName ProductID="Image SLES15-SAP-Azure:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure">
      <FullProductName ProductID="Image SLES15-SAP-Azure:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-Azure-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-Azure-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SAP-Azure-LI-BYOS-Production:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SAP-Azure-LI-BYOS-Production:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SAP-Azure-VLI-BYOS-Production:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SAP-Azure-VLI-BYOS-Production:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SAP-EC2-HVM:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SAP-EC2-HVM:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-EC2-HVM-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-EC2-HVM-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-EC2-HVM-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-EC2-HVM-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-GCE">
      <FullProductName ProductID="Image SLES15-SAP-GCE:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-GCE">
      <FullProductName ProductID="Image SLES15-SAP-GCE:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-GCE-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-GCE-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-GCE-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-GCE-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-OCI-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-OCI-BYOS:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-OCI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SAP-OCI-BYOS">
      <FullProductName ProductID="Image SLES15-SAP-OCI-BYOS:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of Image SLES15-SAP-OCI-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl-1_1-devel-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:libopenssl-1_1-devel-1.1.0i-4.21.1">libopenssl-1_1-devel-1.1.0i-4.21.1 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-1.1.0i-4.21.1">libopenssl1_1-1.1.0i-4.21.1 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-32bit-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-32bit-1.1.0i-4.21.1">libopenssl1_1-32bit-1.1.0i-4.21.1 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-hmac-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-hmac-1.1.0i-4.21.1">libopenssl1_1-hmac-1.1.0i-4.21.1 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-hmac-32bit-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-hmac-32bit-1.1.0i-4.21.1">libopenssl1_1-hmac-32bit-1.1.0i-4.21.1 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.0i-4.21.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:openssl-1_1-1.1.0i-4.21.1">openssl-1_1-1.1.0i-4.21.1 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 bytes. However it also incorrectly allows a nonce to be set of up to 16 bytes. In this case only the last 12 bytes are significant and any additional leading bytes are ignored. It is a requirement of using this cipher that nonce values are unique. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks. If an application changes the default nonce length to be longer than 12 bytes and then makes a change to the leading bytes of the nonce expecting the new value to be a new unique nonce then such an application could inadvertently encrypt messages with a reused nonce. Additionally the ignored bytes in a long nonce are not covered by the integrity guarantee of this cipher. Any application that relies on the integrity of these ignored leading bytes of a long nonce may be further affected. Any OpenSSL internal use of this cipher, including in SSL/TLS, is safe because no such use sets such a long nonce value. However user applications that use this cipher directly and set a non-default nonce length to be longer than 12 bytes may be vulnerable. OpenSSL versions 1.1.1 and 1.1.0 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1c (Affected 1.1.1-1.1.1b). Fixed in OpenSSL 1.1.0k (Affected 1.1.0-1.1.0j).</Note>
    </Notes>
    <CVE>CVE-2019-1543</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container suse/sle15:15.0:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Container suse/sle15:15.0:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-Azure-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-Azure-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-EC2-CHOST-HVM-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-EC2-CHOST-HVM-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-EC2-HVM-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-EC2-HVM-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-GCE-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-GCE-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-OCI-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-OCI-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure-LI-BYOS-Production:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure-LI-BYOS-Production:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure-VLI-BYOS-Production:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure-VLI-BYOS-Production:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-Azure:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-EC2-HVM-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-EC2-HVM-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-EC2-HVM:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-EC2-HVM:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-GCE-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-GCE-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-GCE:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-GCE:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-OCI-BYOS:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>Image SLES15-SAP-OCI-BYOS:openssl-1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:libopenssl-1_1-devel-1.1.0i-4.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-1.1.0i-4.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-32bit-1.1.0i-4.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-hmac-1.1.0i-4.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:libopenssl1_1-hmac-32bit-1.1.0i-4.21.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:openssl-1_1-1.1.0i-4.21.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20190678-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1543.html</URL>
        <Description>CVE-2019-1543</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1128189</URL>
        <Description>SUSE Bug 1128189</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1141801</URL>
        <Description>SUSE Bug 1141801</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1154162</URL>
        <Description>SUSE Bug 1154162</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
