CLSA-2023-1683235759
Dashboard / Vulnerabilities / CLSA-2023-1683235759
CLSA-2023-1683235759
Summary: Fix CVE(s): CVE-2022-3996, CVE-2023-0464, CVE-2023-0466
Details: * SECURITY UPDATE: Excessive resource use verifying X.509 policy constraints - debian/patches/CVE-2023-0464.patch: Limit X.509 certificate tree size to avoid exponential use of computational resources - CVE-2023-0464 * SECURITY UPDATE: Incorrecly documented X509_VERIFY_PARAM_add0_policy() - debian/patches/CVE-2023-0466.patch: Align documentation with actual implementation - CVE-2023-0466 * SECURITY UPDATE: Double locking in X.509 policy cache handling - debian/patches/CVE-2022-3996.patch: Revert previously introduced redundant flag setting and so avoid locking at all - CVE-2022-3996
Affected packages
Package
Name: libssl-dev
Purl: pkg:deb/tuxcare/libssl-dev?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
