Release Info

Advisory: CLSA-2024:1710786990

OS: Ubuntu 16.04 ELS

Public date: 2024-03-18 14:36:32

Project: openssl

Version: 1.0.2g-1ubuntu4.21+tuxcare.els11

Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2024-1710786990.html

Changelog

* SECURITY UPDATE: Potential Denial of Service via processing maliciously formatted PKCS12 file - debian/patches/CVE-2024-0727.patch: Fix decode error causing NULL pointer in PKCS12_unpack_p7data, PKCS12_unpack_p7encdata, PKCS12_unpack_authsafes, SMIME_write_PKCS7, pkcs12_gen_mac and newpass_p12 functions - CVE-2024-0727

Update

Update command: apt-get update apt-get --only-upgrade install openssl*

Packages list

libssl-dev_1.0.2g-1ubuntu4.21+tuxcare.els11_amd64.deb libssl-doc_1.0.2g-1ubuntu4.21+tuxcare.els11_all.deb libssl1.0.0_1.0.2g-1ubuntu4.21+tuxcare.els11_amd64.deb openssl_1.0.2g-1ubuntu4.21+tuxcare.els11_amd64.deb

CVEs

CVE-2024-0727