-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security]  openssl (SSA:2023-038-01)

New openssl packages are available for Slackware 15.0 and -current to
fix security issues.


Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/openssl-1.1.1t-i586-1_slack15.0.txz:  Upgraded.
  This update fixes security issues:
  X.400 address type confusion in X.509 GeneralName.
  Timing Oracle in RSA Decryption.
  Use-after-free following BIO_new_NDEF.
  Double free after calling PEM_read_bio_ex.
  For more information, see:
    https://openssl-library.org/news/secadv/20230207.txt
    https://www.cve.org/CVERecord?id=CVE-2023-0286
    https://www.cve.org/CVERecord?id=CVE-2022-4304
    https://www.cve.org/CVERecord?id=CVE-2023-0215
    https://www.cve.org/CVERecord?id=CVE-2022-4450
  (* Security fix *)
patches/packages/openssl-solibs-1.1.1t-i586-1_slack15.0.txz:  Upgraded.
+--------------------------+


Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
(https://osuosl.org/) for donating FTP and rsync hosting
to the Slackware project!  :-)

Also see the "Get Slack" section on http://www.slackware.com/ for
additional mirror sites near you.

Updated packages for Slackware 15.0:

Updated packages for Slackware x86_64 15.0:

Updated packages for Slackware -current:

Updated packages for Slackware x86_64 -current:


MD5 signatures:
+-------------+

Slackware 15.0 packages:
91957e9cb9b1aafd2c62ee542dcf0b46  openssl-1.1.1t-i586-1_slack15.0.txz
f016aff5335e01db83aa82273c5162e0  openssl-solibs-1.1.1t-i586-1_slack15.0.txz

Slackware x86_64 15.0 packages:
2c7c51349bf330c02664fc5471bb1f02  openssl-1.1.1t-x86_64-1_slack15.0.txz
0d2c9b98fa75eef4f69de0342b3b5521  openssl-solibs-1.1.1t-x86_64-1_slack15.0.txz

Slackware -current packages:
d4cd4df4dad5a7b46b0d83878a7e8420  a/openssl-solibs-1.1.1t-i586-1.txz
849b9ec3e851984ec952bb1587a1e849  n/openssl-1.1.1t-i586-1.txz

Slackware x86_64 -current packages:
012ecd508d7e12f3b437d7d2aa1a9261  a/openssl-solibs-1.1.1t-x86_64-1.txz
0b5e3d4defe82eb8bec1a80180cbf0e5  n/openssl-1.1.1t-x86_64-1.txz


Installation instructions:
+------------------------+

Upgrade the packages as root:
# upgradepkg openssl-1.1.1t-i586-1_slack15.0.txz openssl-solibs-1.1.1t-i586-1_slack15.0.txz


+-----+

Slackware: 2023-038-01: openssl Security Update

February 7, 2023
New openssl packages are available for Slackware 15.0 and -current to fix security issues

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/openssl-1.1.1t-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: X.400 address type confusion in X.509 GeneralName. Timing Oracle in RSA Decryption. Use-after-free following BIO_new_NDEF. Double free after calling PEM_read_bio_ex. For more information, see: https://openssl-library.org/news/secadv/20230207.txt https://www.cve.org/CVERecord?id=CVE-2023-0286 https://www.cve.org/CVERecord?id=CVE-2022-4304 https://www.cve.org/CVERecord?id=CVE-2023-0215 https://www.cve.org/CVERecord?id=CVE-2022-4450 (* Security fix *) patches/packages/openssl-solibs-1.1.1t-i586-1_slack15.0.txz: Upgraded.

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated packages for Slackware 15.0:
Updated packages for Slackware x86_64 15.0:
Updated packages for Slackware -current:
Updated packages for Slackware x86_64 -current:

MD5 Signatures

Slackware 15.0 packages: 91957e9cb9b1aafd2c62ee542dcf0b46 openssl-1.1.1t-i586-1_slack15.0.txz f016aff5335e01db83aa82273c5162e0 openssl-solibs-1.1.1t-i586-1_slack15.0.txz
Slackware x86_64 15.0 packages: 2c7c51349bf330c02664fc5471bb1f02 openssl-1.1.1t-x86_64-1_slack15.0.txz 0d2c9b98fa75eef4f69de0342b3b5521 openssl-solibs-1.1.1t-x86_64-1_slack15.0.txz
Slackware -current packages: d4cd4df4dad5a7b46b0d83878a7e8420 a/openssl-solibs-1.1.1t-i586-1.txz 849b9ec3e851984ec952bb1587a1e849 n/openssl-1.1.1t-i586-1.txz
Slackware x86_64 -current packages: 012ecd508d7e12f3b437d7d2aa1a9261 a/openssl-solibs-1.1.1t-x86_64-1.txz 0b5e3d4defe82eb8bec1a80180cbf0e5 n/openssl-1.1.1t-x86_64-1.txz

Severity
[slackware-security] openssl (SSA:2023-038-01)
New openssl packages are available for Slackware 15.0 and -current to fix security issues.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg openssl-1.1.1t-i586-1_slack15.0.txz openssl-solibs-1.1.1t-i586-1_slack15.0.txz

Related News