Security update for openssl
This update for openssl fixes the following issues: - CVE-2023-0286: Fixed X.400 address type confusion in X.509 GeneralNameFixed (bsc#1207533). - CVE-2023-0215: Fixed a use-after-free following BIO_new_NDEF (bsc#1207536). - CVE-2022-4304: Fixed a timing oracle in RSA decryption (bsc#1207534). The following non-security bug were fixed: - Fix DH key generation in FIPS mode, add support for constant BN for DH parameters (bsc#1202062). - Update further expiring certificates that affect tests (bsc#1201627).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for openssl fixes the following issues: - CVE-2023-0286: Fixed X.400 address type confusion in X.509 GeneralNameFixed (bsc#1207533). - CVE-2023-0215: Fixed a use-after-free following BIO_new_NDEF (bsc#1207536). - CVE-2022-4304: Fixed a timing oracle in RSA decryption (bsc#1207534). The following non-security bug were fixed: - Fix DH key generation in FIPS mode, add support for constant BN for DH parameters (bsc#1202062). - Update further expiring certificates that affect tests (bsc#1201627).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1201627
- https://bugzilla.suse.com/1202062
- https://bugzilla.suse.com/1207533
- https://bugzilla.suse.com/1207534
- https://bugzilla.suse.com/1207536
- https://www.suse.com/security/cve/CVE-2022-4304
- https://www.suse.com/security/cve/CVE-2023-0215
- https://www.suse.com/security/cve/CVE-2023-0286
- https://www.suse.com/support/update/announcement/2023/suse-su-20230684-1/