[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2022:2306-1 -- SLES openssl-3, libopenssl-3-devel, libopenssl3

ID: oval:org.secpod.oval:def:89047815Date: (C)2022-10-28   (M)2024-05-09
Class: PATCHFamily: unix




This update for openssl-3 fixes the following issues: - CVE-2022-2068: Fixed more shell code injection issues in c_rehash. - CVE-2022-1292: Properly sanitise shell metacharacters in c_rehash script. - CVE-2022-1343: Fixed incorrect signature verification in OCSP_basic_verify . - CVE-2022-2097: Fixed partial missing encryption in AES OCB mode . - CVE-2022-1434: Fixed incorrect MAC key used in the RC4-MD5 ciphersuite . - CVE-2022-1473: Fixed resource leakage when decoding certificates and keys .

Platform:
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Server 15 SP4
Product:
openssl-3
libopenssl-3-devel
libopenssl3
Reference:
SUSE-SU-2022:2306-1
CVE-2022-1292
CVE-2022-1343
CVE-2022-1434
CVE-2022-1473
CVE-2022-2068
CVE-2022-2097
CVE    6
CVE-2022-1343
CVE-2022-1473
CVE-2022-1292
CVE-2022-1434
...
CPE    5
cpe:/a:openssl-3:openssl-3
cpe:/a:libopenssl-3-devel:libopenssl-3-devel
cpe:/a:libopenssl3:libopenssl3
cpe:/o:suse:suse_linux_enterprise_server:15:sp4
...

© SecPod Technologies