USN-6119-1: OpenSSL vulnerabilities
Matt Caswell discovered that OpenSSL incorrectly handled certain ASN.1 object identifiers. A remote attacker could possibly use this issue to cause OpenSSL to consume resources, resulting in a denial of service. (CVE-2023-2650) Anton Romanov discovered that OpenSSL incorrectly handled AES-XTS cipher decryption on 64-bit ARM platforms. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-1255)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2023-2650.
What is the severity of CVE-2023-2650?
The severity of CVE-2023-2650 is not specified in the advisory.
How does CVE-2023-2650 affect OpenSSL?
CVE-2023-2650 allows a remote attacker to cause OpenSSL to consume resources, resulting in a denial of service.
Which versions of libssl3 are affected by CVE-2023-2650?
The versions of libssl3 affected by CVE-2023-2650 are 3.0.8-1ubuntu1.2, 3.0.5-2ubuntu2.3, and 3.0.2-0ubuntu1.10.
How do I fix CVE-2023-2650?
To fix CVE-2023-2650, update your libssl3 package to version 3.0.8-1ubuntu1.2, 3.0.5-2ubuntu2.3, or 3.0.2-0ubuntu1.10.