Mageia 2023-0253: openssl security update
Summary
AES-SIV implementation ignores empty associated data entries.
(CVE-2023-2975)
Excessive time spent checking DH keys and parameters. (CVE-2023-3446)
Excessive time spent checking DH q parameter value. (CVE-2023-3817)
References
- https://bugs.mageia.org/show_bug.cgi?id=32112
- https://openssl-library.org/news/secadv/20230714.txt
- https://openssl-library.org/news/secadv/20230719.txt
- https://openssl-library.org/news/secadv/20230731.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2975
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3446
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3817
Resolution
MGASA-2023-0253 - Updated openssl packages fix security vulnerability
SRPMS
- 8/core/openssl-1.1.1v-1.mga8
- 9/core/openssl-3.0.10-1.mga9