=========================================================================Ubuntu Security Notice USN-6188-1
June 22, 2023

openssl vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

OpenSSL could be made to consume resources and cause long
delays if it processed certain input.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

Matt Caswell discovered that OpenSSL incorrectly handled certain ASN.1
object identifiers. A remote attacker could possibly use this issue to
cause OpenSSL to consume resources, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
   libssl1.0.0                     1.0.2g-1ubuntu4.20+esm9
   openssl                         1.0.2g-1ubuntu4.20+esm9

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
   libssl1.0.0                     1.0.1f-1ubuntu2.27+esm9
   openssl                         1.0.1f-1ubuntu2.27+esm9

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6188-1
   CVE-2023-2650

Ubuntu 6188-1: OpenSSL vulnerability

June 22, 2023
OpenSSL could be made to consume resources and cause long delays if it processed certain input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro):   libssl1.0.0                     1.0.2g-1ubuntu4.20+esm9   openssl                         1.0.2g-1ubuntu4.20+esm9 Ubuntu 14.04 LTS (Available with Ubuntu Pro):   libssl1.0.0                     1.0.1f-1ubuntu2.27+esm9   openssl                         1.0.1f-1ubuntu2.27+esm9 After a standard system update you need to reboot your computer to make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-6188-1

  CVE-2023-2650

Severity
June 22, 2023

Package Information

Related News