Uploaded image for project: 'Cloud Enablement'
  1. Cloud Enablement
  2. CLOUD-4167

[JWS57] Important - openssl: Multiple CVEs

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • JWS57 5.7.1-2 GA
    • JWS57 5.7.1-1 GA
    • JWS5
    • None
    • False
    • None
    • False
    • Important

      Fix for openssl CVEs:

      • openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
      • openssl: timing attack in RSA Decryption implementation (CVE-2022-4304)
      • openssl: double free after calling PEM_read_bio_ex (CVE-2022-4450)
      • openssl: use-after-free following BIO_new_NDEF (CVE-2023-0215)
        The fix is in the openssl-libs package.
        https://access.redhat.com/errata/RHSA-2023:1405

       

            szappis@redhat.com Sokratis Zappis
            szappis@redhat.com Sokratis Zappis
            Vasileios Mourikis Vasileios Mourikis (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: