[ubuntu/mantic-security] openssl 3.0.10-1ubuntu2.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Tue Oct 24 15:09:19 UTC 2023


openssl (3.0.10-1ubuntu2.1) mantic-security; urgency=medium

  * SECURITY UPDATE: Incorrect cipher key and IV length processing
    - debian/patches/CVE-2023-5363-1.patch: process key length and iv
      length early if present in crypto/evp/evp_enc.c.
    - debian/patches/CVE-2023-5363-2.patch: add unit test in
      test/evp_extra_test.c.
    - CVE-2023-5363

Date: 2023-10-16 11:50:09.677925+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/openssl/3.0.10-1ubuntu2.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the mantic-changes mailing list