Format: 1.8 Date: Wed, 24 May 2023 13:14:51 -0400 Source: openssl Binary: openssl libssl1.1 libcrypto1.1-udeb libssl1.1-udeb libssl-dev libssl-doc Architecture: amd64 all amd64_translations Version: 1.1.1-1ubuntu2.1~18.04.23 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: libcrypto1.1-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl-doc - Secure Sockets Layer toolkit - development documentation libssl1.1 - Secure Sockets Layer toolkit - shared libraries libssl1.1-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Changes: openssl (1.1.1-1ubuntu2.1~18.04.23) bionic-security; urgency=medium . * SECURITY UPDATE: Possible DoS translating ASN.1 object identifiers - debian/patches/CVE-2023-2650.patch: restrict the size of OBJECT IDENTIFIERs that OBJ_obj2txt will translate in crypto/objects/obj_dat.c. - CVE-2023-2650 * Replace CVE-2022-4304 fix with improved version - debian/patches/CVE-2022-4304.patch: remove previous fix. - debian/patches/CVE-2022-4304-1.patch: use alternative fix in crypto/bn/bn_asm.c, crypto/bn/bn_blind.c, crypto/bn/bn_lib.c, crypto/bn/bn_lcl.h, crypto/rsa/rsa_ossl.c. - debian/patches/CVE-2022-4304-2.patch: re-add BN_F_OSSL_BN_RSA_DO_UNBLIND which was incorrectly removed in include/openssl/bnerr.h. Checksums-Sha1: 2f265b844b328f61831f3b82f974575bb7e44b39 1074572 libcrypto1.1-udeb_1.1.1-1ubuntu2.1~18.04.23_amd64.udeb 943102c3f8b389484cbabcf73a649f93c5711762 1567652 libssl-dev_1.1.1-1ubuntu2.1~18.04.23_amd64.deb 5a4d2d75e84b50f4f60d36e4b62264f84cc9c68f 1489448 libssl-doc_1.1.1-1ubuntu2.1~18.04.23_all.deb db2f8ae6f7a8caf3c8519bc1c49505d12d00c78b 3392280 libssl1.1-dbgsym_1.1.1-1ubuntu2.1~18.04.23_amd64.ddeb d788760030904dcba4fde245b228a5212ffb6b3c 192648 libssl1.1-udeb_1.1.1-1ubuntu2.1~18.04.23_amd64.udeb a2ac09839d2ac3b6309a7bb423187fd07b9934df 1302640 libssl1.1_1.1.1-1ubuntu2.1~18.04.23_amd64.deb 64ae0607084a7b47c70ad7cf910e4430575ed040 549796 openssl-dbgsym_1.1.1-1ubuntu2.1~18.04.23_amd64.ddeb b2a8bac3f6b5d0698b8dca71ed5ea0f992487649 8002 openssl_1.1.1-1ubuntu2.1~18.04.23_amd64.buildinfo 962a82f4a332df08e2c41e6904d5d7c4461f2953 613880 openssl_1.1.1-1ubuntu2.1~18.04.23_amd64.deb a9cad0c804cc931734ed6c9d4798f153ea437395 27049 openssl_1.1.1-1ubuntu2.1~18.04.23_amd64_translations.tar.gz Checksums-Sha256: 1fda245a62a93f18e1832bf86bb9474d96f60be1c23d39f7352bd5068f0fe2fc 1074572 libcrypto1.1-udeb_1.1.1-1ubuntu2.1~18.04.23_amd64.udeb a9b6e93d93e33206836b30630ae8ad720b15bece3da8275184f076e7e97d4b2f 1567652 libssl-dev_1.1.1-1ubuntu2.1~18.04.23_amd64.deb 8758251228d2208670cb17808ff23f06c5a444a66a839eb293a34c80aa21fa32 1489448 libssl-doc_1.1.1-1ubuntu2.1~18.04.23_all.deb 78b541549afd2970d3382a9602a1c222d71de3a495739dadad44409f7f9a948c 3392280 libssl1.1-dbgsym_1.1.1-1ubuntu2.1~18.04.23_amd64.ddeb e3fe0b26f5d475367021d43ec786a5f74301571710a0f8902193df5e688e24fb 192648 libssl1.1-udeb_1.1.1-1ubuntu2.1~18.04.23_amd64.udeb 986727f5a99088bef98971edfcd9567f5693b5e941aa241894fce1020c7015a0 1302640 libssl1.1_1.1.1-1ubuntu2.1~18.04.23_amd64.deb 4ecfc559d6b676c35547c3a5ff61eb00787d17554cbbcb6a6415f55b571745b4 549796 openssl-dbgsym_1.1.1-1ubuntu2.1~18.04.23_amd64.ddeb bfaace2304fae198f2b6b961f69a66f56aef6f936a715df7a8027107e2fc20d0 8002 openssl_1.1.1-1ubuntu2.1~18.04.23_amd64.buildinfo 859c21a32a5101cb151d560333d79a1bc3b66fd22f7c68d16b64365910f33c5e 613880 openssl_1.1.1-1ubuntu2.1~18.04.23_amd64.deb 8077145655ed472a17ed41e7fec8e7f2fd5a248896964c84d8b080c769385818 27049 openssl_1.1.1-1ubuntu2.1~18.04.23_amd64_translations.tar.gz Files: 97a2dc1e7c38cbb38d8a3aada4f8654a 1074572 debian-installer optional libcrypto1.1-udeb_1.1.1-1ubuntu2.1~18.04.23_amd64.udeb 5fa0534b9565c79cd5a7fdd33f010d09 1567652 libdevel optional libssl-dev_1.1.1-1ubuntu2.1~18.04.23_amd64.deb 26643c01cf1de6bac401c463116aea45 1489448 doc optional libssl-doc_1.1.1-1ubuntu2.1~18.04.23_all.deb 1dd6cf9a5bd805016f31e51e4b84fc46 3392280 debug optional libssl1.1-dbgsym_1.1.1-1ubuntu2.1~18.04.23_amd64.ddeb 06f8f44f7d24190b34593d542003f5ca 192648 debian-installer optional libssl1.1-udeb_1.1.1-1ubuntu2.1~18.04.23_amd64.udeb 912ebebd2f49ea2b60441693c66263c9 1302640 libs optional libssl1.1_1.1.1-1ubuntu2.1~18.04.23_amd64.deb aeaa80d3c56924ae89e258c3aa9922d6 549796 debug optional openssl-dbgsym_1.1.1-1ubuntu2.1~18.04.23_amd64.ddeb 97513595e020a62d2e2feaaa8bc4ff49 8002 utils optional openssl_1.1.1-1ubuntu2.1~18.04.23_amd64.buildinfo 12e2125bf1230e7b954b5e4e38e3f788 613880 utils optional openssl_1.1.1-1ubuntu2.1~18.04.23_amd64.deb 9ad57017bc5f411eec779345b8113d1d 27049 raw-translations - openssl_1.1.1-1ubuntu2.1~18.04.23_amd64_translations.tar.gz Original-Maintainer: Debian OpenSSL Team