Security update for openssl-3
This update for openssl-3 fixes the following issues: - CVE-2023-6129: Fixed vector register clobbering on PowerPC. (bsc#1218690) - CVE-2023-6237: Fixed excessive time spent checking invalid RSA public keys. (bsc#1218810) - CVE-2024-0727: Denial of service when processing a maliciously formatted PKCS12 file (bsc#1219243).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for openssl-3 fixes the following issues: - CVE-2023-6129: Fixed vector register clobbering on PowerPC. (bsc#1218690) - CVE-2023-6237: Fixed excessive time spent checking invalid RSA public keys. (bsc#1218810) - CVE-2024-0727: Denial of service when processing a maliciously formatted PKCS12 file (bsc#1219243).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1218690
- https://bugzilla.suse.com/1218810
- https://bugzilla.suse.com/1219243
- https://www.suse.com/security/cve/CVE-2023-6129
- https://www.suse.com/security/cve/CVE-2023-6237
- https://www.suse.com/security/cve/CVE-2024-0727
- https://www.suse.com/support/update/announcement/2024/suse-su-20240518-1/