[GLSA-202103-03] OpenSSL: Multiple vulnerabilities

Severity Normal
Affected Packages 1
Unaffected Packages 1
CVEs 4

Multiple vulnerabilities have been found in OpenSSL, the worst of which could allow remote attackers to cause a Denial of Service condition.

Background
OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer
(SSL v2/v3) and Transport Layer Security (TLS v1/v1.1/v1.2/v1.3) as well
as a general purpose cryptography library.

Description
Multiple vulnerabilities have been discovered in OpenSSL. Please review
the CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All OpenSSL users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/openssl-1.1.1k"

Package Affected Version
pkg:ebuild/dev-libs/openssl?distro=gentoo < 1.1.1k
Package Unaffected Version
pkg:ebuild/dev-libs/openssl?distro=gentoo >= 1.1.1k
ID
GLSA-202103-03
Severity
normal
URL
https://security.gentoo.org/glsa/202103-03
Published
2021-03-31T00:00:00
(3 years ago)
Modified
2021-03-31T00:00:00
(3 years ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2021-23840 CVE-2021-23840 https://nvd.nist.gov/vuln/detail/CVE-2021-23840
CVE CVE-2021-23841 CVE-2021-23841 https://nvd.nist.gov/vuln/detail/CVE-2021-23841
CVE CVE-2021-3449 CVE-2021-3449 https://nvd.nist.gov/vuln/detail/CVE-2021-3449
CVE CVE-2021-3450 CVE-2021-3450 https://nvd.nist.gov/vuln/detail/CVE-2021-3450
Bugzilla 769785 Bugzilla #769785 https://bugs.gentoo.org/show_bug.cgi?id=769785
Bugzilla 777681 Bugzilla #777681 https://bugs.gentoo.org/show_bug.cgi?id=777681
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/dev-libs/openssl?distro=gentoo dev-libs openssl < 1.1.1k gentoo
Unaffected pkg:ebuild/dev-libs/openssl?distro=gentoo dev-libs openssl >= 1.1.1k gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...