Mageia 2023-0273: quictls security update
Summary
The updated packages fix security vulnerabilities:
AES-SIV implementation ignores empty associated data entries.
(CVE-2023-2975)
Excessive time spent checking DH keys and parameters. (CVE-2023-3446)
Excessive time spent checking DH q parameter value. (CVE-2023-3817)
References
- https://bugs.mageia.org/show_bug.cgi?id=32248
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2975
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3446
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3817
- https://openssl-library.org/news/secadv/20230714.txt
- https://openssl-library.org/news/secadv/20230719.txt
- https://openssl-library.org/news/secadv/20230731.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2975
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3446
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3817
Resolution
MGASA-2023-0273 - Updated quictls packages fix security vulnerabilities
SRPMS
- 9/core/quictls-3.0.10-1.mga9