RHSA-2023:7877: Low: openssl security update
Low: openssl security update
Other sources
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Security Fix(es): openssl: Excessive time spent checking DH keys and parameters (CVE-2023-3446) OpenSSL: Excessive time spent checking DH q parameter value (CVE-2023-3817) openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow (CVE-2023-5678) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:7877?
The severity of RHSA-2023:7877 is classified as Low.
How do I fix RHSA-2023:7877?
To fix RHSA-2023:7877, update the affected OpenSSL packages to version 1.1.1k-12.el8_9.
Which systems are affected by RHSA-2023:7877?
RHSA-2023:7877 affects Red Hat Enterprise Linux for x86_64, ARM 64, Power, little endian, and IBM z Systems.
What components are addressed in RHSA-2023:7877?
RHSA-2023:7877 addresses multiple OpenSSL components including openssl, openssl-devel, and openssl-libs.
Is there a specific update package for RHSA-2023:7877?
Yes, the specific update package for RHSA-2023:7877 is version 1.1.1k-12.el8_9 for the OpenSSL library.