Univention Bugzilla – Bug 54557
openssl: Multiple issues (5.0)
Last modified: 2022-03-16 15:18:12 CET
New Debian openssl 1.1.1d-0+deb10u8 fixes: This update addresses the following issues: * Carry propagation bug in the MIPS32 and MIPS64 squaring procedure (CVE-2021-4160) * Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778)
--- mirror/ftp/pool/main/o/openssl/openssl_1.1.1d-0+deb10u7.dsc +++ apt/ucs_5.0-0-errata5.0-1/source/openssl_1.1.1d-0+deb10u8.dsc @@ -1,3 +1,11 @@ +1.1.1d-0+deb10u8 [Mon, 14 Mar 2022 21:10:26 +0100] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: + + * Fix armv8 pointer authentication (Closes: #989604). + * CVE-2022-0778 (Infinite loop in BN_mod_sqrt() reachable when parsing + certificates). + * CVE-2021-4160 (Carry propagation bug in the MIPS32 and MIPS64 squaring + procedure.) + 1.1.1d-0+deb10u7 [Tue, 24 Aug 2021 10:30:43 +0200] Sebastian Andrzej Siewior <sebastian@breakpoint.cc>: * CVE-2021-3711 (SM2 Decryption Buffer Overflow). <http://piuparts.knut.univention.de/5.0-1/#7705374504367321698>
OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-1] 4452ca2c8a Bug #54557: openssl 1.1.1d-0+deb10u8 doc/errata/staging/openssl.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x245>