[ELSA-2023-12213] openssl security update

Severity Important
Affected Packages 6
CVEs 4

[1:1.1.1k-9]
- Fixed Timing Oracle in RSA Decryption
Resolves: CVE-2022-4304
- Fixed Double free after calling PEM_read_bio_ex
Resolves: CVE-2022-4450
- Fixed Use-after-free following BIO_new_NDEF
Resolves: CVE-2023-0215
- Fixed X.400 address type confusion in X.509 GeneralName
Resolves: CVE-2023-0286

[1:1.1.1k-8]
- Fix no-ec build
Resolves: rhbz#2071020

ID
ELSA-2023-12213
Severity
important
URL
https://linux.oracle.com/errata/ELSA-2023-12213.html
Published
2023-03-28T00:00:00
(18 months ago)
Modified
2023-03-28T00:00:00
(18 months ago)
Rights
Copyright 2023 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/openssl?distro=oraclelinux-8.7 oraclelinux openssl < 1.1.1k-9.ksplice1.el8_7 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/openssl-static?distro=oraclelinux-8.7 oraclelinux openssl-static < 1.1.1k-9.ksplice1.el8_7 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/openssl-perl?distro=oraclelinux-8.7 oraclelinux openssl-perl < 1.1.1k-9.ksplice1.el8_7 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/openssl-libs?distro=oraclelinux-8.7 oraclelinux openssl-libs < 1.1.1k-9.ksplice1.el8_7 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/openssl-devel?distro=oraclelinux-8.7 oraclelinux openssl-devel < 1.1.1k-9.ksplice1.el8_7 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/openssl-debugsource?distro=oraclelinux-8.7 oraclelinux openssl-debugsource < 1.1.1k-9.ksplice1.el8_7 oraclelinux-8.7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...