* Added openssl-CVE-2024-41996.patch

OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=117
This commit is contained in:
Pedro Monreal Gonzalez 2024-10-18 08:58:53 +00:00 committed by Git OBS Bridge
parent aaffc1c436
commit 05037720cc
3 changed files with 2 additions and 2 deletions

View File

@ -18,7 +18,7 @@ Thu Sep 19 08:05:52 UTC 2024 - Angel Yankov <angel.yankov@suse.com>
- Security fix: [bsc#1230698, CVE-2024-41996] - Security fix: [bsc#1230698, CVE-2024-41996]
* Validating the order of the public keys in the Diffie-Hellman * Validating the order of the public keys in the Diffie-Hellman
Key Agreement Protocol, when an approved safe prime is used. Key Agreement Protocol, when an approved safe prime is used.
* Added openssl-3-CVE-2024-41996.patch * Added openssl-CVE-2024-41996.patch
------------------------------------------------------------------- -------------------------------------------------------------------
Thu Aug 22 15:18:03 UTC 2024 - Alexander Bergmann <abergmann@suse.com> Thu Aug 22 15:18:03 UTC 2024 - Alexander Bergmann <abergmann@suse.com>

View File

@ -168,7 +168,7 @@ Patch70: openssl-3-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch
# PATCH-FIX-UPSTREAM bsc#1229465 CVE-2024-6119: possible denial of service in X.509 name checks # PATCH-FIX-UPSTREAM bsc#1229465 CVE-2024-6119: possible denial of service in X.509 name checks
Patch71: openssl-CVE-2024-6119.patch Patch71: openssl-CVE-2024-6119.patch
# PATCH-FIX-UPSTREAM bsc#1230698 CVE-2024-41996: Validation order of the DH public keys # PATCH-FIX-UPSTREAM bsc#1230698 CVE-2024-41996: Validation order of the DH public keys
Patch72: openssl-3-CVE-2024-41996.patch Patch72: openssl-CVE-2024-41996.patch
# PATCH-FIX-UPSTREAM bsc#1220262 CVE-2023-50782: Implicit rejection in PKCS#1 v1.5 # PATCH-FIX-UPSTREAM bsc#1220262 CVE-2023-50782: Implicit rejection in PKCS#1 v1.5
Patch73: openssl-CVE-2023-50782.patch Patch73: openssl-CVE-2023-50782.patch
# PATCH-FIX-UPSTREAM bsc#1231741 CVE-2024-9143: low-level invalid GF(2^m) parameters lead to OOB memory access # PATCH-FIX-UPSTREAM bsc#1231741 CVE-2024-9143: low-level invalid GF(2^m) parameters lead to OOB memory access