RHSA-2023:3408: Moderate: openssl security update
Moderate: openssl security update
Other sources
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Security Fix(es): openssl: timing attack in RSA Decryption implementation (CVE-2022-4304) openssl: double free after calling PEMreadbioex (CVE-2022-4450) openssl: use-after-free following BIOnewNDEF (CVE-2023-0215) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6 - Upgrade
Upgrade
redhat/openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6 - Upgrade
Upgrade
redhat/openssl-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6 - Upgrade
Upgrade
redhat/openssl-develto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6 - Upgrade
Upgrade
redhat/openssl-libsto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6 - Upgrade
Upgrade
redhat/openssl-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6 - Upgrade
Upgrade
redhat/openssl-perlto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6.aa - Upgrade
Upgrade
redhat/openssl-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6.aa - Upgrade
Upgrade
redhat/openssl-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6.aa - Upgrade
Upgrade
redhat/openssl-develto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6.aa - Upgrade
Upgrade
redhat/openssl-libsto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6.aa - Upgrade
Upgrade
redhat/openssl-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6.aa - Upgrade
Upgrade
redhat/openssl-perlto a version that resolves this vulnerability.Fixed in 1.1.1k-9.el8_6.aa - Upgrade
Upgrade
opensslto a version that resolves this vulnerability.Patch CVE-2022-4450 - Upgrade
Upgrade
opensslto a version that resolves this vulnerability.Patch CVE-2023-0215 - Upgrade
Upgrade
opensslto a version that resolves this vulnerability.Patch CVE-2022-4304 - Operational
After applying the OpenSSL security update, restart all services linked to the OpenSSL library or reboot the system so the update takes effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3408?
The severity of RHSA-2023:3408 is medium.
How do I fix RHSA-2023:3408?
To fix RHSA-2023:3408, you need to apply the recommended security update provided by Red Hat.
Which software is affected by RHSA-2023:3408?
The software affected by RHSA-2023:3408 is openssl.
Are there any references for RHSA-2023:3408?
Yes, you can find references for RHSA-2023:3408 at the following links: [link1], [link2], [link3].
What are the Common Weakness Enumerations (CWE) associated with RHSA-2023:3408?
The Common Weakness Enumerations (CWE) associated with RHSA-2023:3408 are CWE-416 and CWE-415.