[ELSA-2024-12056] openssl security update
Severity
Moderate
Affected Packages
5
CVEs
3
[1:1.1.1k-12]
- Backport implicit rejection mechanism for RSA PKCS#1 v1.5 to RHEL-8 series
(a proper fix for CVE-2020-25659)
Resolves: RHEL-17696
[1:1.1.1k-11]
- Fix CVE-2023-5678: Generating excessively long X9.42 DH keys or checking
excessively long X9.42 DH keys or parameters may be very slow
Resolves: RHEL-16538
[1:1.1.1k-10]
- Fix CVE-2023-3446: Excessive time spent checking DH keys and parameters
Resolves: RHEL-14245
- Fix CVE-2023-3817: Excessive time spent checking DH q parameter value
Resolves: RHEL-14239
Package | Affected Version |
---|---|
pkg:rpm/oraclelinux/openssl?distro=oraclelinux-8.9 | < 1.1.1k-12.ksplice1.el8_9 |
pkg:rpm/oraclelinux/openssl-static?distro=oraclelinux-8.9 | < 1.1.1k-12.ksplice1.el8_9 |
pkg:rpm/oraclelinux/openssl-perl?distro=oraclelinux-8.9 | < 1.1.1k-12.ksplice1.el8_9 |
pkg:rpm/oraclelinux/openssl-libs?distro=oraclelinux-8.9 | < 1.1.1k-12.ksplice1.el8_9 |
pkg:rpm/oraclelinux/openssl-devel?distro=oraclelinux-8.9 | < 1.1.1k-12.ksplice1.el8_9 |
- ID
- ELSA-2024-12056
- Severity
- moderate
- URL
- https://linux.oracle.com/errata/ELSA-2024-12056.html
- Published
-
2024-01-10T00:00:00
(8 months ago) - Modified
-
2024-01-10T00:00:00
(8 months ago) - Rights
- Copyright 2024 Oracle, Inc.
- Other Advisories
-
- ALAS-2023-1843
- ALAS-2023-1891
- ALAS2-2023-2205
- ALAS2-2023-2226
- ALAS2-2023-2246
- ALAS2-2023-2350
- ALAS2-2023-2351
- ALAS2-2024-2502
- ALPINE:CVE-2023-3446
- ALPINE:CVE-2023-3817
- ALPINE:CVE-2023-5678
- ALSA-2023:7877
- ALSA-2024:0888
- ALSA-2024:2264
- ALSA-2024:2447
- ELSA-2023-7877
- ELSA-2024-0888
- ELSA-2024-2264
- ELSA-2024-2447
- FREEBSD:22DF5074-71CD-11EE-85EB-84A93843EB75
- FREEBSD:A5956603-7E4F-11EE-9DF6-84A93843EB75
- FREEBSD:BAD6588E-2FE0-11EE-A0D1-84A93843EB75
- GLSA-202402-08
- MS:CVE-2023-3817
- RHSA-2023:7877
- RHSA-2024:0888
- RHSA-2024:2264
- RHSA-2024:2447
- RLSA-2024:2264
- SSA:2023-213-01
- SSA:2024-199-01
- SUSE-SU-2023:2961-1
- SUSE-SU-2023:2962-1
- SUSE-SU-2023:2964-1
- SUSE-SU-2023:2965-1
- SUSE-SU-2023:2972-1
- SUSE-SU-2023:2973-1
- SUSE-SU-2023:3011-1
- SUSE-SU-2023:3012-1
- SUSE-SU-2023:3013-1
- SUSE-SU-2023:3093-1
- SUSE-SU-2023:3096-1
- SUSE-SU-2023:3160-1
- SUSE-SU-2023:3179-1
- SUSE-SU-2023:3239-1
- SUSE-SU-2023:3242-1
- SUSE-SU-2023:3243-1
- SUSE-SU-2023:3244-1
- SUSE-SU-2023:3244-2
- SUSE-SU-2023:3291-1
- SUSE-SU-2023:3291-2
- SUSE-SU-2023:3308-1
- SUSE-SU-2023:3338-1
- SUSE-SU-2023:3339-1
- SUSE-SU-2023:3397-1
- SUSE-SU-2023:3958-1
- SUSE-SU-2023:4189-1
- SUSE-SU-2023:4190-1
- SUSE-SU-2023:4488-1
- SUSE-SU-2023:4489-1
- SUSE-SU-2023:4518-1
- SUSE-SU-2023:4519-1
- SUSE-SU-2023:4520-1
- SUSE-SU-2023:4521-1
- SUSE-SU-2023:4522-1
- SUSE-SU-2023:4523-1
- SUSE-SU-2023:4524-1
- SUSE-SU-2023:4593-1
- SUSE-SU-2023:4635-1
- SUSE-SU-2023:4649-1
- SUSE-SU-2023:4918-1
- SUSE-SU-2023:4919-1
- USN-6435-1
- USN-6435-2
- USN-6450-1
- USN-6622-1
- USN-6632-1
- USN-6709-1
- USN-7018-1
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2024-12056 | https://linux.oracle.com/errata/ELSA-2024-12056.html | |
CVE | CVE-2023-5678 | https://linux.oracle.com/cve/CVE-2023-5678.html | |
CVE | CVE-2023-3446 | https://linux.oracle.com/cve/CVE-2023-3446.html | |
CVE | CVE-2023-3817 | https://linux.oracle.com/cve/CVE-2023-3817.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/openssl?distro=oraclelinux-8.9 | oraclelinux | openssl | < 1.1.1k-12.ksplice1.el8_9 | oraclelinux-8.9 | ||
Affected | pkg:rpm/oraclelinux/openssl-static?distro=oraclelinux-8.9 | oraclelinux | openssl-static | < 1.1.1k-12.ksplice1.el8_9 | oraclelinux-8.9 | ||
Affected | pkg:rpm/oraclelinux/openssl-perl?distro=oraclelinux-8.9 | oraclelinux | openssl-perl | < 1.1.1k-12.ksplice1.el8_9 | oraclelinux-8.9 | ||
Affected | pkg:rpm/oraclelinux/openssl-libs?distro=oraclelinux-8.9 | oraclelinux | openssl-libs | < 1.1.1k-12.ksplice1.el8_9 | oraclelinux-8.9 | ||
Affected | pkg:rpm/oraclelinux/openssl-devel?distro=oraclelinux-8.9 | oraclelinux | openssl-devel | < 1.1.1k-12.ksplice1.el8_9 | oraclelinux-8.9 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |