Advisories ยป MGASA-2021-0108

Updated openssl and compat-openssl10 packages fix security vulnerabilities

Publication date: 04 Mar 2021
Modification date: 04 Mar 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-23840 , CVE-2021-23841

Description

Paul Kehrer discovered that OpenSSL incorrectly handled certain input lengths
in EVP functions. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service (CVE-2021-23840).

Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer
fields. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service (CVE-2021-23841).
                

References

SRPMS

7/core

8/core