USN-6986-1: OpenSSL vulnerability
Published Sep 3, 2024
·Updated
David Benjamin discovered that OpenSSL incorrectly handled certain X.509 certificates. An attacker could possible use this issue to cause a denial of service or expose sensitive information.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/libssl3t64<3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.4
Ubuntu Ubuntu=24.04
All of the following
ubuntu/openssl<3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.4
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libssl3<3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.18
Ubuntu Ubuntu=22.04
All of the following
ubuntu/openssl<3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.18
Ubuntu Ubuntu=22.04
Event History
Sep 3, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6986-1?
The severity of USN-6986-1 is considered significant due to the potential for denial of service or exposure of sensitive information.
2
How do I fix USN-6986-1?
To fix USN-6986-1, upgrade to the patched versions of OpenSSL and libssl3 as specified for your Ubuntu version.
3
Which Ubuntu versions are affected by USN-6986-1?
USN-6986-1 affects Ubuntu versions 22.04 and 24.04.
4
What components are impacted by USN-6986-1?
USN-6986-1 impacts the OpenSSL and libssl3 packages.
5
Who discovered the issue related to USN-6986-1?
The vulnerability related to USN-6986-1 was discovered by David Benjamin.