PT-2016-7921 · Apache · Libtcnative-1-0

Published

2016-11-22

·

Updated

2016-11-22

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions libtcnative-1-0 versions prior to 1.1.34
Description The issue is related to the upgrade of libtcnative-1-0 to version 1.1.34, which includes various bugfixes. Specifically, it unconditionally disables export Ciphers and improves ephemeral key handling for DH and ECDH, deriving parameter strength from the certificate key strength by default. Additionally, APIs SSL.generateRSATempKey() and SSL.loadDSATempKey() are no longer supported.
Recommendations Upgrade to libtcnative-1-0 version 1.1.34 to fix the issue. As a temporary workaround, consider disabling the use of export Ciphers and restricting access to the SSL.generateRSATempKey() and SSL.loadDSATempKey() APIs until the update is applied.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

SUSE-SU-2016:2871-1

Affected Products

Libtcnative-1-0