[ELSA-2022-9225] openssl security update

Severity Important
Affected Packages 5
CVEs 1

[1.0.2k-24.0.3]
- fix CVE-2022-0778 openssl: Fix possible infinite loop in BN_mod_sqrt()
- Change Epoch from 1 to 10
- Fix DH self-test to add shared secret comparison [Orabug: 32467026]
- Add DH support changes for SP 800-56A rev3 requirements [Orabug: 32467059]
- Add TLS KDF self-test [Orabug: 32467193]
- Add EC keys pairwise consistency test [Orabug: 32467059]

[1.0.2k-24]
- Updates patch openssl-1.0.2k-cve-2021-3712.patch to only free on push failure.
- Resolves: rhbz#2039993

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/openssl?distro=oraclelinux-7.9 oraclelinux openssl < 1.0.2k-24.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-static?distro=oraclelinux-7.9 oraclelinux openssl-static < 1.0.2k-24.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-perl?distro=oraclelinux-7.9 oraclelinux openssl-perl < 1.0.2k-24.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-libs?distro=oraclelinux-7.9 oraclelinux openssl-libs < 1.0.2k-24.0.3.el7_9_fips oraclelinux-7.9
Affected pkg:rpm/oraclelinux/openssl-devel?distro=oraclelinux-7.9 oraclelinux openssl-devel < 1.0.2k-24.0.3.el7_9_fips oraclelinux-7.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...