MGASA-2023-0253 - Updated openssl packages fix security vulnerability Publication date: 11 Sep 2023 URL: https://advisories.mageia.org/MGASA-2023-0253.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-2975, CVE-2023-3446, CVE-2023-3817 AES-SIV implementation ignores empty associated data entries. (CVE-2023-2975) Excessive time spent checking DH keys and parameters. (CVE-2023-3446) Excessive time spent checking DH q parameter value. (CVE-2023-3817) References: - https://bugs.mageia.org/show_bug.cgi?id=32112 - https://www.openssl.org/news/secadv/20230714.txt - https://www.openssl.org/news/secadv/20230719.txt - https://www.openssl.org/news/secadv/20230731.txt - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2975 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3446 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3817 SRPMS: - 8/core/openssl-1.1.1v-1.mga8 - 9/core/openssl-3.0.10-1.mga9