MGASA-2021-0108
Dashboard / Vulnerabilities / MGASA-2021-0108
MGASA-2021-0108
Summary: Updated openssl and compat-openssl10 packages fix security vulnerabilities
Details: Paul Kehrer discovered that OpenSSL incorrectly handled certain input lengths in EVP functions. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service (CVE-2021-23840). Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer fields. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service (CVE-2021-23841).
References: https://advisories.mageia.org/MGASA-2021-0108.html, https://bugs.mageia.org/show_bug.cgi?id=28383, https://www.openssl.org/news/secadv/20210216.txt, https://ubuntu.com/security/notices/USN-4738-1
Affected packages
Package
Name: openssl
Purl: pkg:rpm/mageia/openssl?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
