SUSE-SU-2023:4635-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4635-1
SUSE-SU-2023:4635-1
Summary: Security update for openssl-3
Details: This update for openssl-3 fixes the following issues: - CVE-2023-5678: Fixed generating and checking of excessively long X9.42 DH keys that resulted in a possible Denial of Service (bsc#1216922). Bug fixes: - The default /etc/ssl/openssl3.cnf file will include any configuration files that other packages might place into /etc/ssl/engines3.d/ and /etc/ssl/engdef3.d/. - Create the two new necessary directores for the above patch. [bsc#1194187, bsc#1207472]
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234635-1/, https://bugzilla.suse.com/1194187, https://bugzilla.suse.com/1207472, https://bugzilla.suse.com/1216922, https://www.suse.com/security/cve/CVE-2023-5678
Affected packages
Package
Name: openssl-3
Purl: pkg:rpm/suse/openssl-3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
