[ubuntu/bionic-updates] openssl1.0 1.0.2n-1ubuntu5.12 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Tue Apr 25 13:28:39 UTC 2023


openssl1.0 (1.0.2n-1ubuntu5.12) bionic-security; urgency=medium

  * SECURITY UPDATE: excessive resource use when verifying policy constraints
    - debian/patches/CVE-2023-0464.patch: limit the number of nodes created in
      a policy tree (the default limit is set to 1000 nodes).
    - CVE-2023-0464
  * SECURITY UPDATE: invalid certificate policies ignored in leaf certificates
    - debian/patches/CVE-2023-0465.patch: ensure that EXFLAG_INVALID_POLICY is
      checked even in leaf certs.
    - CVE-2023-0466
  * SECURITY UPDATE: certificate policy check in X509_VERIFY_PARAM_add0_policy
    not enabled as documented
    - debian/patches/CVE-2023-0466.patch: fix documentation of
      X509_VERIFY_PARAM_add0_policy().
    - CVE-2023-0466

Date: 2023-04-18 18:34:09.142536+00:00
Changed-By: Camila Camargo de Matos <camila.camargodematos at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.12
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list