The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741) References: . MGASA-2024-0200 - Updated openssl packages fix security vulnerabilities Publication date: 31 May 2024 URL: https://advisories.mageia.org/MGASA-2024-0200.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-4603, CVE-2024-4741 The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741) References: - https://bugs.mageia.org/show_bug.cgi?id=33224 - https://openssl-library.org/news/secadv/20240516.txt - https://openssl-library.org/news/secadv/20240528.txt - https://www.cve.org/CVERecord?id=CVE-2024-4603 - https://www.cve.org/CVERecord?id=CVE-2024-4741 SRPMS: - 9/core/openssl-3.0.13-1.1.mga9 . Mageia's recent patch tackles significant vulnerabilities in openssl, focusing on redundant DSA key validations and safeguarding memory integrity.. Mageia Security Advisory, OpenSSL Update, CVE Threat Management. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.