New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 5.8
Synopsis
The remote SuSE 10 host is missing a security-related patch.
Description
This update of openssl fixes a off-by-one buffer overflow in function SSL_get_shared_ciphers(). This vulnerability potentially allows remote code execution; depending on memory layout of the process.
(CVE-2007-5135)
We released updates for openssl already, but an update for the compat 0.9.7g openssl libraries was missing and is provided with this patch.
Solution
Apply ZYPP patch number 5055.