Alerts This Week
Warning Icon 1 1,153
Alerts This Week
Warning Icon 1 1,153

Ubuntu 18.04, 16.04 LTS USN-6632-1: Critical OpenSSL Denial of Service

ubuntu
Calendar Grey February 13, 2024
Dist Ubuntu Esm H88
The Ubuntu Security Notice USN-6633-1 informs users about vulnerabilities in OpenSSL impacting LTS versions, which could result in potential service interruptions.
Several security issues were fixed in OpenSSL.

Summary

Several security issues were fixed in OpenSSL.

Software Description:

- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

David Benjamin discovered that OpenSSL incorrectly handled excessively long

X9.42 DH keys. A remote attacker could possibly use this issue to cause

OpenSSL to consume resources, leading to a denial of service.

(CVE-2023-5678)

Bahaa Naamneh discovered that OpenSSL incorrectly handled certain malformed

PKCS12 files. A remote attacker could possibly use this issue to cause

OpenSSL to crash, resulting in a denial of service. (CVE-2024-0727)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
   libssl1.1                       1.1.1-1ubuntu2.1~18.04.23+esm4

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
   libssl1.0.0                     1.0.2g-1ubuntu4.20+esm11

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-6632-1

  CVE-2023-5678, CVE-2024-0727

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6632-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here