RHSA-2024:0154: Low: openssl security update
Low: openssl security update
Other sources
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Security Fix(es): openssl: Excessive time spent checking DH keys and parameters (CVE-2023-3446) OpenSSL: Excessive time spent checking DH q parameter value (CVE-2023-3817) openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow (CVE-2023-5678) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): openssl: Excessive time spent checking DH q parameter value (JIRA:RHEL-14238) openssl: Excessive time spent checking DH keys and parameters (JIRA:RHEL-14244) openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow (JIRA:RHEL-16537)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0154?
The severity of RHSA-2024:0154 is classified as Low.
How do I fix RHSA-2024:0154?
To fix RHSA-2024:0154, update the affected packages to version 1.1.1k-12.el8_8.
Which software is affected by RHSA-2024:0154?
RHSA-2024:0154 affects various OpenSSL packages within Red Hat Enterprise Linux for IBM z Systems.
Is RHSA-2024:0154 a critical vulnerability?
No, RHSA-2024:0154 is not a critical vulnerability; it is classified as low severity.
What should I do if I am using the impacted OpenSSL version from RHSA-2024:0154?
If you are using the impacted OpenSSL version, it is recommended to apply the security update to mitigate potential risks.