[ALAS2-2024-2478] Amazon Linux 2 2017.12 - ALAS2-2024-2478: low priority package update for openssl11
Severity
Low
Affected Packages
15
CVEs
1
Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2024-0727:
Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack
The package openssl098e is provided purely for binary compatibility with older Amazon Linux versions. It does not receive security updates.
- ID
- ALAS2-2024-2478
- Severity
- low
- URL
- https://alas.aws.amazon.com/AL2/ALAS-2024-2478.html
- Published
-
2024-02-29T10:03:00
(6 months ago) - Modified
-
2024-02-29T10:03:00
(6 months ago) - Rights
- Amazon Linux Security Team
- Other Advisories
-
- ALAS2-2024-2479
- ALAS2-2024-2483
- ALAS2-2024-2502
- ALPINE:CVE-2024-0727
- ALSA-2024:2447
- ELSA-2024-2447
- FREEBSD:10DEE731-C069-11EE-9190-84A93843EB75
- RHSA-2024:2447
- SSA:2024-199-01
- SUSE-SU-2024:0518-1
- SUSE-SU-2024:0549-1
- SUSE-SU-2024:0813-1
- SUSE-SU-2024:0814-1
- SUSE-SU-2024:0815-1
- SUSE-SU-2024:0831-1
- SUSE-SU-2024:0832-1
- SUSE-SU-2024:0833-1
- SUSE-SU-2024:0840-1
- SUSE-SU-2024:0841-1
- SUSE-SU-2024:0842-1
- USN-6622-1
- USN-6632-1
- USN-6709-1
- USN-7018-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2024-0727 | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0727 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/amazonlinux/openssl11?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11 | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11 | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11 | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-static?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-static | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-static?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-static | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-static?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-static | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-libs?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-libs | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-libs?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-libs | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-libs?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-libs | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-devel?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-devel | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-devel?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-devel | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-devel?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-devel | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-debuginfo?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-debuginfo | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-debuginfo?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-debuginfo | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-debuginfo?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-debuginfo | < 1.1.1g-12.amzn2.0.20 | amazonlinux-2 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |