|
|
Subscribe / Log in / New account

Mageia alert MGASA-2023-0253 (openssl)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2023-0253: Updated openssl packages fix security vulnerability
Date:  Mon, 11 Sep 2023 15:08:58 +0200
Message-ID:  <20230911130858.F22B29FE7D@duvel.mageia.org>
Archive-link:  Article

MGASA-2023-0253 - Updated openssl packages fix security vulnerability Publication date: 11 Sep 2023 URL: https://advisories.mageia.org/MGASA-2023-0253.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-2975, CVE-2023-3446, CVE-2023-3817 Description: AES-SIV implementation ignores empty associated data entries. (CVE-2023-2975) Excessive time spent checking DH keys and parameters. (CVE-2023-3446) Excessive time spent checking DH q parameter value. (CVE-2023-3817) References: - https://bugs.mageia.org/show_bug.cgi?id=32112 - https://www.openssl.org/news/secadv/20230714.txt - https://www.openssl.org/news/secadv/20230719.txt - https://www.openssl.org/news/secadv/20230731.txt - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2975 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3446 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3817 SRPMS: - 8/core/openssl-1.1.1v-1.mga8 - 9/core/openssl-3.0.10-1.mga9


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds