RHSA-2023:3722MediumCVSS 6.5
Red Hat Security Advisory: openssl security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-0464 — openssl: Denial of service by excessive resource usage in verifying X509 policy constraints CVE-2023-0465 — openssl: Invalid certificate policies in leaf certificates are silently ignored CVE-2023-0466 — openssl: Certificate policy check not enabled CVE-2023-1255 — openssl: Input buffer over-read in AES-XTS implementation on 64 bit ARM CVE-2023-2650 — openssl: Possible DoS translating ASN.1 object identifiers
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2023:3722
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175860
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175864
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175873
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178029
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178030
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178034
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178137
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181082
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182561
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2207947
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3722.json