openssl 3.0.10-1ubuntu4 source package in Ubuntu
Changelog
openssl (3.0.10-1ubuntu4) noble; urgency=medium * SECURITY UPDATE: Excessive time spent in DH check / generation with large Q parameter value - debian/patches/CVE-2023-5678.patch: make DH_check_pub_key() and DH_generate_key() safer yet in crypto/dh/dh_check.c, crypto/dh/dh_err.c, crypto/dh/dh_key.c, crypto/err/openssl.txt, include/crypto/dherr.h, include/openssl/dh.h, include/openssl/dherr.h. - CVE-2023-5678 * SECURITY UPDATE: POLY1305 MAC implementation corrupts vector registers on PowerPC - debian/patches/CVE-2023-6129.patch: fix vector register clobbering in crypto/poly1305/asm/poly1305-ppc.pl. - CVE-2023-6129 * SECURITY UPDATE: Excessive time spent checking invalid RSA public keys - debian/patches/CVE-2023-6237.patch: limit the execution time of RSA public key check in crypto/rsa/rsa_sp800_56b_check.c, test/recipes/91-test_pkey_check.t, test/recipes/91-test_pkey_check_data/rsapub_17k.pem. - CVE-2023-6237 * SECURITY UPDATE: PKCS12 Decoding crashes - debian/patches/CVE-2024-0727.patch: add NULL checks where ContentInfo data can be NULL in crypto/pkcs12/p12_add.c, crypto/pkcs12/p12_mutl.c, crypto/pkcs12/p12_npas.c, crypto/pkcs7/pk7_mime.c. - CVE-2024-0727 -- Marc Deslauriers <email address hidden> Wed, 31 Jan 2024 13:03:16 -0500
Upload details
- Uploaded by:
- Marc Deslauriers
- Uploaded to:
- Noble
- Original maintainer:
- Ubuntu Developers
- Architectures:
- any all
- Section:
- utils
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
openssl_3.0.10.orig.tar.gz | 14.5 MiB | 1761d4f5b13a1028b9b6f3d4b8e17feb0cedc9370f6afe61d7193d2cdce83323 |
openssl_3.0.10-1ubuntu4.debian.tar.xz | 124.8 KiB | c65188925a3af07c7cd441fbf1bc1e2f8ee731cdb257056e7295d1890885f85c |
openssl_3.0.10-1ubuntu4.dsc | 2.4 KiB | d1341c748c7dfa01657ef9351f1c3c9437cf694caa041bd84d773e4cf0143b08 |
Available diffs
Binary packages built by this source
- libssl-dev: Secure Sockets Layer toolkit - development files
This package is part of the OpenSSL project's implementation of the SSL
and TLS cryptographic protocols for secure communication over the
Internet.
.
It contains development libraries, header files, and manpages for libssl
and libcrypto.
- libssl-doc: Secure Sockets Layer toolkit - development documentation
This package is part of the OpenSSL project's implementation of the SSL
and TLS cryptographic protocols for secure communication over the
Internet.
.
It contains manpages and demo files for libssl and libcrypto.
- libssl3: Secure Sockets Layer toolkit - shared libraries
This package is part of the OpenSSL project's implementation of the SSL
and TLS cryptographic protocols for secure communication over the
Internet.
.
It provides the libssl and libcrypto shared libraries.
- libssl3-dbgsym: debug symbols for libssl3
- openssl: Secure Sockets Layer toolkit - cryptographic utility
This package is part of the OpenSSL project's implementation of the SSL
and TLS cryptographic protocols for secure communication over the
Internet.
.
It contains the general-purpose command line binary /usr/bin/openssl,
useful for cryptographic operations such as:
* creating RSA, DH, and DSA key parameters;
* creating X.509 certificates, CSRs, and CRLs;
* calculating message digests;
* encrypting and decrypting with ciphers;
* testing SSL/TLS clients and servers;
* handling S/MIME signed or encrypted mail.
- openssl-dbgsym: debug symbols for openssl