Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: MGASA-2024-0200 Critical: OpenSSL Memory Safety Risk

mageia
Calendar Grey May 31, 2024
Dist Mageia Esm H88
Mageia's recent patch tackles significant vulnerabilities in openssl, focusing on redundant DSA key validations and safeguarding memory integrity.
The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters

Summary

The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741)

References

- https://bugs.mageia.org/show_bug.cgi?id=33224

- https://openssl-library.org/news/secadv/20240516.txt

- https://openssl-library.org/news/secadv/20240528.txt

- https://www.cve.org/CVERecord?id=CVE-2024-4603

- https://www.cve.org/CVERecord?id=CVE-2024-4741

Resolution

SRPMS

- 9/core/openssl-3.0.13-1.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 31 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0200.html
Type: security
CVE: CVE-2024-4603, CVE-2024-4741

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here