Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Mageia 8 & 9: MGASA-2023-0253 Moderate: OpenSSL Excessive Check Issues

mageia
Calendar Grey September 11, 2023
Dist Mageia Esm H88
The latest version of OpenSSL packages available for Mageia mitigates serious security flaws identified in CVEs released on September 11, 2023.
AES-SIV implementation ignores empty associated data entries

Summary

AES-SIV implementation ignores empty associated data entries. (CVE-2023-2975)
Excessive time spent checking DH keys and parameters. (CVE-2023-3446)
Excessive time spent checking DH q parameter value. (CVE-2023-3817)

References

- https://bugs.mageia.org/show_bug.cgi?id=32112

- https://openssl-library.org/news/secadv/20230714.txt

- https://openssl-library.org/news/secadv/20230719.txt

- https://openssl-library.org/news/secadv/20230731.txt

- https://www.cve.org/CVERecord?id=CVE-2023-2975

- https://www.cve.org/CVERecord?id=CVE-2023-3446

- https://www.cve.org/CVERecord?id=CVE-2023-3817

Resolution

SRPMS

- 8/core/openssl-1.1.1v-1.mga8

- 9/core/openssl-3.0.10-1.mga9

Publication date: 11 Sep 2023
URL: https://advisories.mageia.org/MGASA-2023-0253.html
Type: security
CVE: CVE-2023-2975, CVE-2023-3446, CVE-2023-3817

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here