MGASA-2024-0200 - Updated openssl packages fix security vulnerabilities

Publication date: 31 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0200.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-4603,
     CVE-2024-4741

The updated packages fix security vulnerabilities:
Excessive time spent checking DSA keys and parameters. (CVE-2024-4603)
Use After Free with SSL_free_buffers. (CVE-2024-4741)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33224
- https://www.openssl.org/news/secadv/20240516.txt
- https://www.openssl.org/news/secadv/20240528.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4603
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4741

SRPMS:
- 9/core/openssl-3.0.13-1.1.mga9

Mageia 2024-0200: openssl Security Advisory Updates

The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters

Summary

The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741)

References

- https://bugs.mageia.org/show_bug.cgi?id=33224

- https://www.openssl.org/news/secadv/20240516.txt

- https://www.openssl.org/news/secadv/20240528.txt

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4603

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4741

Resolution

MGASA-2024-0200 - Updated openssl packages fix security vulnerabilities

SRPMS

- 9/core/openssl-3.0.13-1.1.mga9

Severity
Publication date: 31 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0200.html
Type: security
CVE: CVE-2024-4603, CVE-2024-4741

Related News