[USN-6450-1] OpenSSL vulnerabilities

Severity High
Affected Packages 12
CVEs 4

Several security issues were fixed in OpenSSL.

Tony Battersby discovered that OpenSSL incorrectly handled key and
initialization vector (IV) lengths. This could lead to truncation issues
and result in loss of confidentiality for some symmetric cipher modes.
(CVE-2023-5363)

Juerg Wullschleger discovered that OpenSSL incorrectly handled the AES-SIV
cipher. This could lead to empty data entries being ignored, resulting in
certain applications being misled. This issue only affected Ubuntu 22.04
LTS and Ubuntu 23.04. (CVE-2023-2975)

It was discovered that OpenSSL incorrectly handled checking excessively
long DH keys or parameters. A remote attacker could possibly use this issue
to cause OpenSSL to consume resources, leading to a denial of service. This
issue only affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2023-3446,
CVE-2023-3817)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/openssl?distro=mantic ubuntu openssl < 3.0.10-1ubuntu2.1 mantic
Affected pkg:deb/ubuntu/openssl?distro=lunar ubuntu openssl < 3.0.8-1ubuntu1.4 lunar
Affected pkg:deb/ubuntu/openssl?distro=jammy ubuntu openssl < 3.0.2-0ubuntu1.12 jammy
Affected pkg:deb/ubuntu/libssl3?distro=mantic ubuntu libssl3 < 3.0.10-1ubuntu2.1 mantic
Affected pkg:deb/ubuntu/libssl3?distro=lunar ubuntu libssl3 < 3.0.8-1ubuntu1.4 lunar
Affected pkg:deb/ubuntu/libssl3?distro=jammy ubuntu libssl3 < 3.0.2-0ubuntu1.12 jammy
Affected pkg:deb/ubuntu/libssl-doc?distro=mantic ubuntu libssl-doc < 3.0.10-1ubuntu2.1 mantic
Affected pkg:deb/ubuntu/libssl-doc?distro=lunar ubuntu libssl-doc < 3.0.8-1ubuntu1.4 lunar
Affected pkg:deb/ubuntu/libssl-doc?distro=jammy ubuntu libssl-doc < 3.0.2-0ubuntu1.12 jammy
Affected pkg:deb/ubuntu/libssl-dev?distro=mantic ubuntu libssl-dev < 3.0.10-1ubuntu2.1 mantic
Affected pkg:deb/ubuntu/libssl-dev?distro=lunar ubuntu libssl-dev < 3.0.8-1ubuntu1.4 lunar
Affected pkg:deb/ubuntu/libssl-dev?distro=jammy ubuntu libssl-dev < 3.0.2-0ubuntu1.12 jammy
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...