SUSE-SU-2023:2046-1

    Dashboard / Vulnerabilities / SUSE-SU-2023:2046-1

    SUSE-SU-2023:2046-1

    Published: 26 Apr 2023Last Modified: 26 Apr 2023

    Summary: Security update for openssl-ibmca

    Details: This update for openssl-ibmca fixes the following issues: Upgraded openssl-ibmca to version 2.4.0 (bsc#1210058) - Provider: Adjustments for OpenSSL versions 3.1 and 3.2 - Provider: Support RSA blinding - Provider: Constant-time fixes for RSA PKCS#1 v1.5 and OAEP padding - Provider: Support 'implicit rejection' option for RSA PKCS#1 v1.5 padding - Provider: Adjustments in OpenSSL config generator and example configs - Engine: EC: Cache ICA key in EC_KEY object (performance improvement) - FIPS 140-3: Correct engine handling so only the ciphers selected in the config file are activated (bsc#1210359)

    Affected packages

    Package

    Name: openssl-ibmca

    Purl: pkg:rpm/suse/openssl-ibmca&distro=SUSE%20Linux%20Enterprise%20Micro%205.4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.4.0-150400.4.8.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2023:2046-1 | CVE-DB