[CLSA-2024:1710786990] Fix CVE(s): CVE-2024-0727
Type:
security
Severity:
Moderate
Release date:
2024-03-18 18:36:33 UTC
Description:
* SECURITY UPDATE: Potential Denial of Service via processing maliciously formatted PKCS12 file - debian/patches/CVE-2024-0727.patch: Fix decode error causing NULL pointer in PKCS12_unpack_p7data, PKCS12_unpack_p7encdata, PKCS12_unpack_authsafes, SMIME_write_PKCS7, pkcs12_gen_mac and newpass_p12 functions - CVE-2024-0727
Updated packages:
  • libssl-dev_1.0.2g-1ubuntu4.21+tuxcare.els11_amd64.deb
    sha:f5fa1ecd40023e0fb346bed53a6a62759121ac82
  • libssl-doc_1.0.2g-1ubuntu4.21+tuxcare.els11_all.deb
    sha:b2227b34ab92540a3484933591833758dd61b224
  • libssl1.0.0_1.0.2g-1ubuntu4.21+tuxcare.els11_amd64.deb
    sha:3d9cb742525e43a3df48f2d8fdecaabb06134bfb
  • openssl_1.0.2g-1ubuntu4.21+tuxcare.els11_amd64.deb
    sha:dc9aa384953f3b698634ade68088bd4691ef476f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.