RHSA-2024:0208: Low: openssl security update
Low: openssl security update
Other sources
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Security Fix(es): openssl: Excessive time spent checking DH keys and parameters (CVE-2023-3446) OpenSSL: Excessive time spent checking DH q parameter value (CVE-2023-3817) openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow (CVE-2023-5678) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): openssl: Excessive time spent checking DH q parameter value (JIRA:RHEL-14237) openssl: Excessive time spent checking DH keys and parameters (JIRA:RHEL-14243) openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow (JIRA:RHEL-16536)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0208?
The severity of RHSA-2024:0208 is classified as low.
Which software is affected by RHSA-2024:0208?
RHSA-2024:0208 affects OpenSSL versions prior to 1.1.1k-12.el8_6 on Red Hat Enterprise Linux for IBM z Systems.
How do I fix RHSA-2024:0208?
To remediate RHSA-2024:0208, install the updated OpenSSL package version 1.1.1k-12.el8_6 or later.
Is there a specific package to upgrade for RHSA-2024:0208?
Yes, you should upgrade the OpenSSL package to version 1.1.1k-12.el8_6.
What are the recommended actions for RHSA-2024:0208?
It is recommended to apply the security update and verify the installation of the fixed OpenSSL packages.