Updated openssl packages fix security vulnerability
Publication date: 11 Sep 2023Modification date: 11 Sep 2023
Type: security
Affected Mageia releases : 8 , 9
CVE: CVE-2023-2975 , CVE-2023-3446 , CVE-2023-3817
Description
AES-SIV implementation ignores empty associated data entries. (CVE-2023-2975) Excessive time spent checking DH keys and parameters. (CVE-2023-3446) Excessive time spent checking DH q parameter value. (CVE-2023-3817)
References
- https://bugs.mageia.org/show_bug.cgi?id=32112
- https://www.openssl.org/news/secadv/20230714.txt
- https://www.openssl.org/news/secadv/20230719.txt
- https://www.openssl.org/news/secadv/20230731.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2975
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3446
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3817
SRPMS
8/core
- openssl-1.1.1v-1.mga8
9/core
- openssl-3.0.10-1.mga9