-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 May 2023 23:30:44 +0200 Source: openssl Binary: libcrypto1.1-udeb libssl-dev libssl1.1 libssl1.1-dbgsym libssl1.1-udeb openssl openssl-dbgsym Architecture: i386 Version: 1.1.1n-0+deb11u5 Distribution: bullseye-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Sebastian Andrzej Siewior Description: libcrypto1.1-udeb - Secure Sockets Layer toolkit - libcrypto udeb (udeb) libssl-dev - Secure Sockets Layer toolkit - development files libssl1.1 - Secure Sockets Layer toolkit - shared libraries libssl1.1-udeb - ssl shared library - udeb (udeb) openssl - Secure Sockets Layer toolkit - cryptographic utility Closes: 1034720 Changes: openssl (1.1.1n-0+deb11u5) bullseye-security; urgency=medium . * CVE-2023-0464 (Excessive Resource Usage Verifying X.509 Policy Constraints) (Closes: #1034720). * CVE-2023-0465 (Invalid certificate policies in leaf certificates are silently ignored). * CVE-2023-0466 (Certificate policy check not enabled). * Alternative fix for CVE-2022-4304 (Timing Oracle in RSA Decryption). * CVE-2023-2650 (Possible DoS translating ASN.1 object identifiers). Checksums-Sha1: f64fce3e9e3b62c038bce4a46d7344345b060f62 1085592 libcrypto1.1-udeb_1.1.1n-0+deb11u5_i386.udeb 371b2d8e0e5707221be98caca24866ea00b639f0 1845620 libssl-dev_1.1.1n-0+deb11u5_i386.deb 7930d495dd5687764277232701d527d6ed6fdda8 2372084 libssl1.1-dbgsym_1.1.1n-0+deb11u5_i386.deb 6fb11c5296f707e7ec0daf0586fced1bbf65866c 208612 libssl1.1-udeb_1.1.1n-0+deb11u5_i386.udeb a13f7bfbed9366c294a8da44ad9b3208d88b684d 1554576 libssl1.1_1.1.1n-0+deb11u5_i386.deb da1c06dd45f549b8cb060b86e5daa6e4530b6a00 481060 openssl-dbgsym_1.1.1n-0+deb11u5_i386.deb cb323de2c6a7aea4279f36c2bc129bbebf332ef0 7636 openssl_1.1.1n-0+deb11u5_i386-buildd.buildinfo 8fe56c67479aa6c2407bd0c931e37b1c65e926ed 863912 openssl_1.1.1n-0+deb11u5_i386.deb Checksums-Sha256: baa357af87a1f2f6af41ae0fc3e36b5a8989a890907bd50d4761bbaecd6244a0 1085592 libcrypto1.1-udeb_1.1.1n-0+deb11u5_i386.udeb 59b4908f607b196b7a78a623ebacc428833f93cceeb2caa58cb5df635961d20a 1845620 libssl-dev_1.1.1n-0+deb11u5_i386.deb b4796367ce99151566286b37fb61afe98048c7f5aab45a6012bf2d2d6f39f340 2372084 libssl1.1-dbgsym_1.1.1n-0+deb11u5_i386.deb bf1aa397d629d3b35623da6454a5e64c289b5b6461e832af5ae65a3e9908b1b1 208612 libssl1.1-udeb_1.1.1n-0+deb11u5_i386.udeb fb00d56ee39171882f36c0629a74d7cef75a76c74afbf8402740d56e2ff18e98 1554576 libssl1.1_1.1.1n-0+deb11u5_i386.deb 3482e8740c8b56b4c0a147210458e26a97af6872bf4cc726efa6ec739e088def 481060 openssl-dbgsym_1.1.1n-0+deb11u5_i386.deb 57b48c79ce53cc626cfd37c27ed1e7f435b2a31fc717abdb21e6b9cd19a41d23 7636 openssl_1.1.1n-0+deb11u5_i386-buildd.buildinfo 70b9214689ca953e551b578cf71bd6a39daf6809f84dcaaa2f425a85c920ab59 863912 openssl_1.1.1n-0+deb11u5_i386.deb Files: 19a99cc91215e3cda0f7918f35987228 1085592 debian-installer optional libcrypto1.1-udeb_1.1.1n-0+deb11u5_i386.udeb 38431d4a07ba5de5f6f1bc2774550262 1845620 libdevel optional libssl-dev_1.1.1n-0+deb11u5_i386.deb 96c66a7b0cec45226d75c7f3a2a6b353 2372084 debug optional libssl1.1-dbgsym_1.1.1n-0+deb11u5_i386.deb eda3cb75f75baa75238d736a190071fa 208612 debian-installer optional libssl1.1-udeb_1.1.1n-0+deb11u5_i386.udeb 680534610474f788d0c165d8bc9f2898 1554576 libs optional libssl1.1_1.1.1n-0+deb11u5_i386.deb 1eec75db953a41407b842ea420287ed9 481060 debug optional openssl-dbgsym_1.1.1n-0+deb11u5_i386.deb 555e205935640892327a925c0edd87e5 7636 utils optional openssl_1.1.1n-0+deb11u5_i386-buildd.buildinfo bc0e018502e8246ae09c246afb50b93c 863912 utils optional openssl_1.1.1n-0+deb11u5_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7bJOCbihllHz5a8G6bGbnoZY/NwFAmR0iocACgkQ6bGbnoZY /NyHlg//e+xARMk8fm3Slgw4flMEwFEoWgj79jKZ/tqt363iZ72L9KN29lW9wEYw m73ax8LubKRqdcFkvOPJV/ndJV7OUsllu673DFsopR2VyVfMnGOGwjUHNaNk3DYp P1aCEVFicUDqhou7cHGJDlXzTfNxVt8uvKfz9KN1JD7CfQPX6cqOnchuR3Tkm/Hm qBf7gI/6hqIhmQR0rHzilkhmBtkywNSb7z0XS+UnIlnOU9VI7Uxv29X5dHRVfSLD LR29Y7UJpcIaEqLT2MGmvDWdMITypDEDXBjR5YvtMeEHIO9U5wVEj1uAzGndxtWj G2+20RQt2fPg+XQ36jzxkQwDObe7rLeOkOU3lBK2XLuWZIU0PQqAIJIdtiIE/HTy hUA9oMnUMX0Q+snY5w7xO3WDSHJ1lYM4mB6h5s5hr2BUt9B5+fnKg4jiKMSLNgHQ IXcGvtMxHahjGH4kWrNwhgoo7/d8TAONdTgfP9LmNg0gIqiFCQIeulQYZjV+IxHu Js3sFLE5xC9N83jBntGDrVbTlocjbPBaRKYLDpnMhD713VYyPuwiHDwf+N6LWr69 kYTmx22sH7GiWbahzl6cd+VCDQSmGzvKIlwPkQ/QfrYaRmccedeXl+alhJxlx6Q9 uoTcU38ZbwD3CAh5kaAEErSM/EOWEvlWD/ZATvEqwPy2yBmeYSw= =V6ZE -----END PGP SIGNATURE-----