[ALAS2-2024-2478] Amazon Linux 2 2017.12 - ALAS2-2024-2478: low priority package update for openssl11

Severity Low
Affected Packages 15
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2024-0727:
Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack

The package openssl098e is provided purely for binary compatibility with older Amazon Linux versions. It does not receive security updates.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/openssl11?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11 < 1.1.1g-12.amzn2.0.20 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11?arch=i686&distro=amazonlinux-2 amazonlinux openssl11 < 1.1.1g-12.amzn2.0.20 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11 < 1.1.1g-12.amzn2.0.20 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-static?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-static < 1.1.1g-12.amzn2.0.20 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-static?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-static < 1.1.1g-12.amzn2.0.20 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-static?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-static < 1.1.1g-12.amzn2.0.20 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-libs?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-libs < 1.1.1g-12.amzn2.0.20 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-libs?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-libs < 1.1.1g-12.amzn2.0.20 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-libs?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-libs < 1.1.1g-12.amzn2.0.20 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-devel?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-devel < 1.1.1g-12.amzn2.0.20 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-devel?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-devel < 1.1.1g-12.amzn2.0.20 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-devel?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-devel < 1.1.1g-12.amzn2.0.20 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-debuginfo < 1.1.1g-12.amzn2.0.20 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-debuginfo < 1.1.1g-12.amzn2.0.20 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-debuginfo < 1.1.1g-12.amzn2.0.20 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...