-
Bug
-
Resolution: Done
-
Major
-
JWS57 5.7.1-1 GA
-
None
Fix for openssl CVEs:
- openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
- openssl: timing attack in RSA Decryption implementation (CVE-2022-4304)
- openssl: double free after calling PEM_read_bio_ex (CVE-2022-4450)
- openssl: use-after-free following BIO_new_NDEF (CVE-2023-0215)
The fix is in the openssl-libs package.
https://access.redhat.com/errata/RHSA-2023:1405