-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 May 2023 23:30:44 +0200 Source: openssl Binary: libcrypto1.1-udeb libssl-dev libssl1.1 libssl1.1-dbgsym libssl1.1-udeb openssl openssl-dbgsym Architecture: amd64 Version: 1.1.1n-0+deb11u5 Distribution: bullseye-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Sebastian Andrzej Siewior Description: libcrypto1.1-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl1.1 - Secure Sockets Layer toolkit - shared libraries libssl1.1-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Closes: 1034720 Changes: openssl (1.1.1n-0+deb11u5) bullseye-security; urgency=medium . * CVE-2023-0464 (Excessive Resource Usage Verifying X.509 Policy Constraints) (Closes: #1034720). * CVE-2023-0465 (Invalid certificate policies in leaf certificates are silently ignored). * CVE-2023-0466 (Certificate policy check not enabled). * Alternative fix for CVE-2022-4304 (Timing Oracle in RSA Decryption). * CVE-2023-2650 (Possible DoS translating ASN.1 object identifiers). Checksums-Sha1: fff0f583d7cee0fc9d39a13c5b7b4363c27c42dc 1105432 libcrypto1.1-udeb_1.1.1n-0+deb11u5_amd64.udeb 539b9e089ec6fda0d38e70ddc30c48259d83f031 1814756 libssl-dev_1.1.1n-0+deb11u5_amd64.deb 260dae24683f98905ce21f932ab6caeebe5a475f 3058436 libssl1.1-dbgsym_1.1.1n-0+deb11u5_amd64.deb cc99a91030aa2f94bec896b549db1a7a934fca52 191816 libssl1.1-udeb_1.1.1n-0+deb11u5_amd64.udeb e8a80e4821679f43e796d2932830be21ab484344 1558508 libssl1.1_1.1.1n-0+deb11u5_amd64.deb 394050791abbe5fe8c2763585b69d1c789e36816 555708 openssl-dbgsym_1.1.1n-0+deb11u5_amd64.deb e6ea3b08c4e214eb740821d054e68a1d0a31c2cf 7696 openssl_1.1.1n-0+deb11u5_amd64-buildd.buildinfo e87d3ee4182dc3e1cd658f0853781b1207355cd5 854096 openssl_1.1.1n-0+deb11u5_amd64.deb Checksums-Sha256: 7cce4560d623a2b76a17ec2b83833b960e62d145fe3449db42230703957f3f95 1105432 libcrypto1.1-udeb_1.1.1n-0+deb11u5_amd64.udeb 7a4223dcf4acb9a03bfcbdffbffeb46fec49a0e6189e36af0b47604921bdaab3 1814756 libssl-dev_1.1.1n-0+deb11u5_amd64.deb 87e9f90599a4c70e595cb64381f074e7d96585049d16324352d7d7a939fded15 3058436 libssl1.1-dbgsym_1.1.1n-0+deb11u5_amd64.deb 1474326e68e2cce5544b258e195fe354a4cededbbc073bb16ae08fe5deba69b0 191816 libssl1.1-udeb_1.1.1n-0+deb11u5_amd64.udeb 08be73a6a5454a8978c5a71ea5ca4b3a6909ce6cc927890729ebd6f9af12d9d8 1558508 libssl1.1_1.1.1n-0+deb11u5_amd64.deb e3ac97d6d5b2f2a58dc53711a8a50ff54ca78297b5e1010b849dccbf18d44506 555708 openssl-dbgsym_1.1.1n-0+deb11u5_amd64.deb 270cde7240efa3100c3f9dc2ad066979c7f87529c293a6d1e55d1c8a06df5fb5 7696 openssl_1.1.1n-0+deb11u5_amd64-buildd.buildinfo 9756f315ef74ccaa1b741b5359c886b10fdb531ea6bfba0f9b4ae9e635c8af86 854096 openssl_1.1.1n-0+deb11u5_amd64.deb Files: 0ff28ec053f0338d10a7b37033dc2aa3 1105432 debian-installer optional libcrypto1.1-udeb_1.1.1n-0+deb11u5_amd64.udeb c3913ece4f71d6e3cbf753d78d9facd2 1814756 libdevel optional libssl-dev_1.1.1n-0+deb11u5_amd64.deb abf58de54e05204de8253651e6619712 3058436 debug optional libssl1.1-dbgsym_1.1.1n-0+deb11u5_amd64.deb fc8b9102793dd2c5455e55071975b9b0 191816 debian-installer optional libssl1.1-udeb_1.1.1n-0+deb11u5_amd64.udeb 97b50992fec27b761c5b68575432839f 1558508 libs optional libssl1.1_1.1.1n-0+deb11u5_amd64.deb e96c75f31017d82d1c249818d7213cf7 555708 debug optional openssl-dbgsym_1.1.1n-0+deb11u5_amd64.deb aad077ea6faaae6bf8f847b594c88e3b 7696 utils optional openssl_1.1.1n-0+deb11u5_amd64-buildd.buildinfo e24d5dfd49b70ad9445c51891c17c8b5 854096 utils optional openssl_1.1.1n-0+deb11u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJyRdn7p9tGRfxctAots23/koc0EFAmR0ikwACgkQots23/ko c0E3PA//bxTKaYLgRQRhcB/qixuLzCKYTcGJ6J/Ee9Y+TXS54goxDqk7AVnH2DNn 3tpEBgKVYAys3aIkNM0YcdvXiPuVcr3cTln5i5ZD8cgZq/ZmTC1e781D22tPBQJ6 N8kqgM0eYDHUvbkmm/ks6Cdp0pL8EynQQrxxVY8Av9gdjYdw2W2Dpg+t3pAGUZ5K D/ZTxH7xWkT+p0GTTMbT/a7Do6pzvtD2ZH+pSUxmE805PWBqA+VGRFSZUaEeJ0e8 6ABgqEqiUasEjYIYeKuPXXZsnS9+YlO81IBKZT22jBebw/6eABm3umFa5EXR41ha rHJGcR4tPGIj9AahLD6tGnObgJFc2ogEMY03E66D75WzkFsHgIWSq0xY43yLQ38E wpbiJulil+5rfy0zDJEpgRskdqBqxE084Kto35kFj3313X4tgQfOTOw8QlRrn5oX J0TkmNcTgYx/M+YjoQxY2bYI4wcRmPrvUVwe06sWUsEJtqI2Z58a30LKUSU2yxCB WWcKg3JBCAyNYEYcEx4Hlj9kvTtoNXDud6Rar5NTpdV0KFhVg2nwGe+cOEFu8c+W dEOMHvFkowcv1qSDN6FEz0vQfsI51gM27pRwV5pSpc8erms/DjJ0loLvDWnmeaUK yVcR7xcGLJtZh0/acaBr1DdhBMT66Nvg+Cyo/zNjXR4o3OX/rjs= =GXd7 -----END PGP SIGNATURE-----