Format: 1.8 Date: Wed, 31 Jan 2024 15:45:27 -0500 Source: openssl Binary: libcrypto1.1-udeb libssl-dev libssl1.1 libssl1.1-udeb openssl Architecture: arm64 arm64_translations Version: 1.1.1f-1ubuntu2.21 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: libcrypto1.1-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl1.1 - Secure Sockets Layer toolkit - shared libraries libssl1.1-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Changes: openssl (1.1.1f-1ubuntu2.21) focal-security; urgency=medium . * SECURITY UPDATE: Excessive time spent in DH check / generation with large Q parameter value - debian/patches/CVE-2023-5678.patch: make DH_check_pub_key() and DH_generate_key() safer yet in crypto/dh/dh_check.c, crypto/dh/dh_err.c, crypto/dh/dh_key.c, crypto/err/openssl.txt, include/openssl/dh.h, include/openssl/dherr.h. - CVE-2023-5678 * SECURITY UPDATE: PKCS12 Decoding crashes - debian/patches/CVE-2024-0727.patch: add NULL checks where ContentInfo data can be NULL in crypto/pkcs12/p12_add.c, crypto/pkcs12/p12_mutl.c, crypto/pkcs12/p12_npas.c, crypto/pkcs7/pk7_mime.c. - CVE-2024-0727 Checksums-Sha1: dc7149cf6cdce0b0c4f6384706843f4a8b985a30 947108 libcrypto1.1-udeb_1.1.1f-1ubuntu2.21_arm64.udeb 2889c3f477b3b576b886b3f45241468187b5b771 1459844 libssl-dev_1.1.1f-1ubuntu2.21_arm64.deb 9fd69394dd9398ec6dc20fc9de4964968d804cbd 2886464 libssl1.1-dbgsym_1.1.1f-1ubuntu2.21_arm64.ddeb fb2c83e9a86b14950f3a86bb940dce215cc43699 172360 libssl1.1-udeb_1.1.1f-1ubuntu2.21_arm64.udeb 778897d836d53a7de544038e2af25c37f5725b07 1157192 libssl1.1_1.1.1f-1ubuntu2.21_arm64.deb 468c42744ad0ee8734779020936ac53bc3ae9fd7 546092 openssl-dbgsym_1.1.1f-1ubuntu2.21_arm64.ddeb 214e336ea5e0d36545590ad79b14b67c47ba6d69 7439 openssl_1.1.1f-1ubuntu2.21_arm64.buildinfo c345151f635f655a737b48e07e5b0a2ddcffab4e 599288 openssl_1.1.1f-1ubuntu2.21_arm64.deb 7b88e3e66b493f7e831657eeb60b933af6fc35d8 27374 openssl_1.1.1f-1ubuntu2.21_arm64_translations.tar.gz Checksums-Sha256: a360d1f80aa51386a241b42d3e80f98c8991eb2ae23e24255b6d303bbc80a0d4 947108 libcrypto1.1-udeb_1.1.1f-1ubuntu2.21_arm64.udeb 79d116214150810d44ff14b25d07432edcc12866c3087e5ed846e53856b17330 1459844 libssl-dev_1.1.1f-1ubuntu2.21_arm64.deb 01c5bc6b9485484e3b5a890087c657231ef2446d713b8e5ed390cc82cb407595 2886464 libssl1.1-dbgsym_1.1.1f-1ubuntu2.21_arm64.ddeb 3ece92bb285fa863818a17b117933e1a1e5271f9d19d854c5d9aff866c0e1667 172360 libssl1.1-udeb_1.1.1f-1ubuntu2.21_arm64.udeb 8c00e510989c245ca442258f1456f739665fe4fda52e41a093b46b539f5fd8bb 1157192 libssl1.1_1.1.1f-1ubuntu2.21_arm64.deb f5c854b1e00f1a2db38940b2b9968db81814aaddb2a30c352746a827e6f2758d 546092 openssl-dbgsym_1.1.1f-1ubuntu2.21_arm64.ddeb ec7ccbc619c6e38dae954bf844677c673d515403dc2dc99b7341ff4851cd8b58 7439 openssl_1.1.1f-1ubuntu2.21_arm64.buildinfo c47eb72e26785951a5852af51bb60fefa86356415cee10e0999dfd1eb9538405 599288 openssl_1.1.1f-1ubuntu2.21_arm64.deb 3372bd1bf1d35cfe8c3de24d76e0eb525b9587f5da3482778251a4dc4bc83edb 27374 openssl_1.1.1f-1ubuntu2.21_arm64_translations.tar.gz Files: b8f79339d86b3fd90d0f6c7e727352ab 947108 debian-installer optional libcrypto1.1-udeb_1.1.1f-1ubuntu2.21_arm64.udeb 4ad757624eebad3d6cdc33461a54ed44 1459844 libdevel optional libssl-dev_1.1.1f-1ubuntu2.21_arm64.deb 1bb6ccedfd9b8599b3431fc9563e34ac 2886464 debug optional libssl1.1-dbgsym_1.1.1f-1ubuntu2.21_arm64.ddeb 7a516bc8df761c9610b5351fd8e5dbab 172360 debian-installer optional libssl1.1-udeb_1.1.1f-1ubuntu2.21_arm64.udeb 32bd55b859a8480ee2c5842df4661302 1157192 libs optional libssl1.1_1.1.1f-1ubuntu2.21_arm64.deb 3a9590b211fc531a91a606ac9558b256 546092 debug optional openssl-dbgsym_1.1.1f-1ubuntu2.21_arm64.ddeb c056c79163ce3d0977b84457924b83b2 7439 utils optional openssl_1.1.1f-1ubuntu2.21_arm64.buildinfo 45fed97383d586727b3ef9219b75171d 599288 utils optional openssl_1.1.1f-1ubuntu2.21_arm64.deb b042d8397776066157b3c1b6e8ea9165 27374 raw-translations - openssl_1.1.1f-1ubuntu2.21_arm64_translations.tar.gz Original-Maintainer: Debian OpenSSL Team