Format: 1.8 Date: Wed, 24 May 2023 13:14:51 -0400 Source: openssl Binary: libcrypto1.1-udeb libssl-dev libssl1.1 libssl1.1-udeb openssl Architecture: armhf armhf_translations Version: 1.1.1f-1ubuntu2.19 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: libcrypto1.1-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl1.1 - Secure Sockets Layer toolkit - shared libraries libssl1.1-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Changes: openssl (1.1.1f-1ubuntu2.19) focal-security; urgency=medium . * SECURITY UPDATE: Possible DoS translating ASN.1 object identifiers - debian/patches/CVE-2023-2650.patch: restrict the size of OBJECT IDENTIFIERs that OBJ_obj2txt will translate in crypto/objects/obj_dat.c. - CVE-2023-2650 * Replace CVE-2022-4304 fix with improved version - debian/patches/CVE-2022-4304.patch: remove previous fix. - debian/patches/CVE-2022-4304-1.patch: use alternative fix in crypto/bn/bn_asm.c, crypto/bn/bn_blind.c, crypto/bn/bn_lib.c, crypto/bn/bn_local.h, crypto/rsa/rsa_ossl.c. - debian/patches/CVE-2022-4304-2.patch: re-add BN_F_OSSL_BN_RSA_DO_UNBLIND which was incorrectly removed in include/openssl/bnerr.h. Checksums-Sha1: 486bb0e7b30df84d571002a85f5710de83f03f56 890252 libcrypto1.1-udeb_1.1.1f-1ubuntu2.19_armhf.udeb 953fe8eaee388fd9378fb8b06ec7a39a005e3063 1382424 libssl-dev_1.1.1f-1ubuntu2.19_armhf.deb a100c0426a0b39981a0a6adf845d96638d3bc5cf 2844880 libssl1.1-dbgsym_1.1.1f-1ubuntu2.19_armhf.ddeb d2465bb5b1c09fc8fa9876ff33082ae85a8646ec 156076 libssl1.1-udeb_1.1.1f-1ubuntu2.19_armhf.udeb 4bfcfeff34b608c5e397a13b8f950df483e55a77 1083292 libssl1.1_1.1.1f-1ubuntu2.19_armhf.deb c632eb51a39d99a766c251619d38b179856bcd75 522344 openssl-dbgsym_1.1.1f-1ubuntu2.19_armhf.ddeb 8ad28da3449e723c801aaf9a6d5ac3178a05cadc 7324 openssl_1.1.1f-1ubuntu2.19_armhf.buildinfo cfbb88acc778cae6059f202bba9ea579fcf22c12 597828 openssl_1.1.1f-1ubuntu2.19_armhf.deb fbcf9b1f0cd076ba2d4bf20ebb146e207ca5b368 27256 openssl_1.1.1f-1ubuntu2.19_armhf_translations.tar.gz Checksums-Sha256: 2bdbb32bd2388f30d39e0e008d980b3599f2483adcd87f8e81bd3eb9f89e2305 890252 libcrypto1.1-udeb_1.1.1f-1ubuntu2.19_armhf.udeb 304a50e5d2d0e0743d922238035e6575751f05cd02a06a0ed181584e6ed76f39 1382424 libssl-dev_1.1.1f-1ubuntu2.19_armhf.deb 2331ef63def9e69b6a9dc087d3db0a279a30c92b5ba234724794679d226522d2 2844880 libssl1.1-dbgsym_1.1.1f-1ubuntu2.19_armhf.ddeb 80a894ee367d6a6d1837def321ad5b35cc0bc2b59ef38379dbcdc893a15c68f3 156076 libssl1.1-udeb_1.1.1f-1ubuntu2.19_armhf.udeb a8bc000440b9c3f053262398a05501e576c4257fe13ecc43b634af30498b5e58 1083292 libssl1.1_1.1.1f-1ubuntu2.19_armhf.deb 41d2d3e2730a1c9dd0b2e7adb99432e09364ab6520841a8404a3b2cfb9f799c0 522344 openssl-dbgsym_1.1.1f-1ubuntu2.19_armhf.ddeb 8901b9b7b13819690b2c5b946135126fe750945c5bdffd352a74c40721c83b51 7324 openssl_1.1.1f-1ubuntu2.19_armhf.buildinfo 903de3ac962b50a62af7ae8edb47b4d61f517a8239a5ea2c04d0cccf17de8e40 597828 openssl_1.1.1f-1ubuntu2.19_armhf.deb b5cec0ec66c16a5fd8adb466609d326c003419995badbfded33c2d2818368c64 27256 openssl_1.1.1f-1ubuntu2.19_armhf_translations.tar.gz Files: 13ceb5040a452b788c259058be1f07c1 890252 debian-installer optional libcrypto1.1-udeb_1.1.1f-1ubuntu2.19_armhf.udeb 83d6b48cef8e1f712e694b48704d5421 1382424 libdevel optional libssl-dev_1.1.1f-1ubuntu2.19_armhf.deb b6d6abca5cf4d698f770505011563f8b 2844880 debug optional libssl1.1-dbgsym_1.1.1f-1ubuntu2.19_armhf.ddeb a7a6ff1e4f07a2d3590d2cba51638dd5 156076 debian-installer optional libssl1.1-udeb_1.1.1f-1ubuntu2.19_armhf.udeb 423d3bbf979cf0e490a6f821764ea9e5 1083292 libs optional libssl1.1_1.1.1f-1ubuntu2.19_armhf.deb 42cf7b906213a689ad18ee17c5d7d028 522344 debug optional openssl-dbgsym_1.1.1f-1ubuntu2.19_armhf.ddeb 7d2d5dfdf715643229ef669b9660a667 7324 utils optional openssl_1.1.1f-1ubuntu2.19_armhf.buildinfo 1fdae8a153b33566a99ac8064ca71368 597828 utils optional openssl_1.1.1f-1ubuntu2.19_armhf.deb e3cfb434a3090c70906862bc72d03ce4 27256 raw-translations - openssl_1.1.1f-1ubuntu2.19_armhf_translations.tar.gz Original-Maintainer: Debian OpenSSL Team