SUSE-SU-2023:4649-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4649-1
SUSE-SU-2023:4649-1
Summary: Security update for openssl-3
Details: This update for openssl-3 fixes the following issues: - CVE-2023-5678: Fixed generating and checking of excessively long X9.42 DH keys that resulted in a possible Denial of Service (bsc#1216922). Bug fixes: - The default /etc/ssl/openssl3.cnf file will include any configuration files that other packages might place into /etc/ssl/engines3.d/ and /etc/ssl/engdef3.d/. - Create the two new necessary directores for the above. [bsc#1194187, bsc#1207472]
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234649-1/, https://bugzilla.suse.com/1194187, https://bugzilla.suse.com/1207472, https://bugzilla.suse.com/1216922, https://www.suse.com/security/cve/CVE-2023-5678
Affected packages
Package
Name: openssl-3
Purl: pkg:rpm/suse/openssl-3&distro=SUSE%20Linux%20Enterprise%20Micro%205.3
Affected ranges
Type: ECOSYSTEM
Events:
