[ELSA-2021-9121] openssl bug fix update

Severity Important
Affected Packages 5
CVEs 1

[1.0.2k-21]
- remove ASN1_F_ASN1_ITEM_EMBED_D2I from openssl-1.0.2k-cve-2020-1971.patch

[1.0.2k-20]
- fix CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference

[1.0.2k-19]
- close the RSA decryption 9 lives of Bleichenbacher cat
timing side channel (#1649568)

[1.0.2k-18]
- fix CVE-2018-0734 - DSA signature local timing side channel
- fix CVE-2019-1559 - 0-byte record padding oracle
- close the RSA decryption One & done EM side channel (#1619558)

[1.0.2k-17]
- use SHA-256 in FIPS RSA pairwise key check
- fix CVE-2018-5407 (and CVE-2018-0735) - EC signature local
timing side-channel key extraction

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/openssl?distro=oraclelinux-7.9 oraclelinux openssl < 1.0.2k-21.ksplice1.el7_9 oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-static?distro=oraclelinux-7.9 oraclelinux openssl-static < 1.0.2k-21.ksplice1.el7_9 oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-perl?distro=oraclelinux-7.9 oraclelinux openssl-perl < 1.0.2k-21.ksplice1.el7_9 oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-libs?distro=oraclelinux-7.9 oraclelinux openssl-libs < 1.0.2k-21.ksplice1.el7_9 oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-devel?distro=oraclelinux-7.9 oraclelinux openssl-devel < 1.0.2k-21.ksplice1.el7_9 oraclelinux-7.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...