Thursday, May 23, 2024

[USN-6663-3] OpenSSL update

-----BEGIN PGP PUBLIC KEY BLOCK-----

xsFNBGT1vF8BEAC2w6Af0VgaEvUzWv6T0qj98y+DqoSm76w3SdXg1rTgR/pX3a9c
tlfnoCZcyeSf+ttUnkha9vyzFfhz0u5IFDehqadQyfBCxemeEA+b1KBhSMGpiuRd
KMwOggQObp7oGdjImQRDT2CfQOWg1KsVk2o4lIuYZNcg8BWSyVlKxXEJ+hKmeDmO
P53rzY7l/gSHaeJ2bpYY5dCw0OLVLb/3QdrPthvYg4zvGzgvVwEKGsocADboqFYk
GuffEuYe1DYOCXbAx6Q59ZP/V7IlIFE9kiUpOAAAf6r/qkVBm3Zj4DtTuTMipsdJ
A6cQvvuMx9Qm37u7fOhosdNczZ2Zt38bLu9Gz2oL9mG0YBCe8Qfgf+pXLc6BKOLB
dwymVtV43cz7vlDOhRojWpsVxggV1FecjJ+cdP4FWAusE11ST60pY/W+y61MLzfs
qy3O3MIoQjXBaEGGTtPiEpVeZL+1v8aJuB5sJLAj56OmgSpcc7NqBHwUgjoeMA4y
87utHUSr4II/Ay1H4xOEZoCE+vIC61G32TwTco3WMhtISSOnRZHsc6GRuBeVr5fq
xEvmmo8lG+u5IgDpakbC/OpDxzemCiYJWCiUgF7X7VnlLLBVyxUMv9P1edursuk1
E2W5sl7RYIiPos23YU/Q66rER/egPX6YmsAr38FcqGYh9ZOauSfmKQ0pDwARAQAB
zVVEYXZpZCBGZXJuYW5kZXogR29uemFsZXogKFNpZ24gKyBlbmNyeXB0IGtleSkg
PGRhdmlkLmZlcm5hbmRlemdvbnphbGV6QGNhbm9uaWNhbC5jb20+wsGUBBMBCgA+
FiEELi4vmPVwZWdpuqdqlvdwxzm8Ws4FAmT1vF8CGwMFCQICKQAFCwkIBwIGFQoJ
CAsCBBYCAwECHgECF4AACgkQlvdwxzm8Ws5bUBAAkWPMosnc2/qqCyLSxkO5ACoT
p527SNCSJU0oQqHghxa7dLQr4NrjMsiNIR3GzVl+IeOR3BvIIwGl3VwQ110dAegX
kQ7jSq6k5bMT9UWJ5O6ju47cxQ1QzYwp5xD1rel8CPouvHHoqIGF0IWB74/BDPRK
7HPsip0P/mQFDaqm/lfxJXE9ZX/nsrqfzQpPMMyChXQbkMYr3Nw5j5AiOwHIZX2c
NksAiziNhzqjK5zPRYLIAwMuFgSyAOoBQamclRbPSNEV5A4D+jOflFy4II636ZEh
gs8+e8ggMb4tCofgolHLOzgzOReClVed6jegQI3rU/YFiyA8oC5pEnTk3qnc6Uzd
Fsrmh8nj2sSElcIf6HL2AITyzbja6MHSbNa5yoVqePQNZySYn+odOHA5TETR8U1p
KGs5oNQvMvWIW+o8t8m+di/a3vwzl9M4HnwCAM513qnv5Bqt/qucedCSFNQvf0Xs
f+2YxWckYC6w0QjJyvR22zYrhd4K87rr6HTu+qeonnivU1ePSc6SMEbvHS8uWgh0
nN+qCxkh4UzqBL2qnkRxB3VGF1peLGPjefmIkGt236B9/xkEcSOD7ZHz9xa00jQx
3tDLTHnelsLvk8gnIaBku0cnMtCo5DUyOH04pKif7uhbPLkNbEy4zyD9ga2hoX5R
gkeELpyDEi6bhMs66z/OwU0EZPW8XwEQAM/loHx2tM4KYXFBrQmsaFlOHFHTrj80
hMWDM4KEXo9+ufaXZnoJFAjo4Dmh+MT4Xcfs1ooowoWlik6nDQ6DwYtk237YwK/f
s4H/SbZ/p3uwdN+vCcXcQm5lUf927iVALCE9jJBwZrfr5EA808elZZzQSCT05lMm
lnHICso+l1qjysReXb6mzFqGGvgRtU9HnvkFKW8dx4W/++VVSJP7tf2aKVcpyWj4
GrS8I+4S6RYDMlUGNky1/fZWZsuJPv0Prv6NqhS/8QbwpI3b0RwK//ZF7ur8KIHE
+fiA8weqxHGQG0pAOZNgCjc5YF9sz4ooMZMhQHKVRknNVcGng6HORaZJkKtZKRHd
kCDo0DrQLiKmlKo8DkZozv9YFVxyoYESAfcxLhnKiaRT/RE6QLt85VUItPl8lEQh
1erCt74VG5UoIW+sE5Lz/xAjwPMK5XUwIZJJHEp/RVRqMzyxoqM0vIexS+CfFn0X
0Ayew3oEL4oguF4NJRb609I25tKFQU/b+AiTvA2DkiZ1hH5yk6kgg4VS21czCDJB
5UoZ8FgGdSP/PN8DQZ50X0A1x2VO83Pje5FhlEUKVs2eKbb48989RNCcYNwHy2lY
Ch3o4HzfS+Zhf2lgljoNJrj/rsSGanMFCmLcLZqQWaNN3I3suuDBr8IZJJiKP/SE
OyoV3lWFnQGhABEBAAHCwXwEGAEKACYWIQQuLi+Y9XBlZ2m6p2qW93DHObxazgUC
ZPW8XwIbDAUJAgIpAAAKCRCW93DHObxazqt5D/938SB3G2m5LzR5aYgBpn3C5arg
O3QO0JHsmzXXzCRZ0f8hPVZPNiuii3UwTX4v4eDcgi8MZnaEmxG0vQosal28Yd6f
jJdwNUv74K68N7xB5kAlwC/jONbAeSmod3EwUq8vKINseV/IzBux/uX3CBwvDpGi
a6v/h0EzuF5HQjguvu7/JSuVxP6y0aJ4gECmOJQMtppSlFBXzD5U6E2X6v6zHvqY
tkgwn00Y9J+V60+vncxAGfSJtcLOceAY2rEmj1bl8rhRCTcacImyh0HKfIST+v9o
Jx+opSyHo1RjhwcbmSoc3U5CGZx+y05H/WceQgett5qOZAGUDZhprTt+j/+scrAR
zZf0zzlpkao8UoergBMYc8iTmJ54/iQSxrk1WjS7OecP45oV7fwBNkQZeZuPITnD
0VP/RPpjd4Qz6eDWaccZPCrS785I0Onylygn5aOktDPU3eOmEhrHMuG+JSjfVqbi
m7jVqPFjWg3Loprmpwa1CGd2039Pa/jWfwh0bxsosSdf09kVj+UvlH4Y85Ve57LU
q9U+cpekCs/VZdL277tiMA2uFvQDSepwmQdBUYxkJSffVfK/cJhzZdY0FjsiVySl
kLVKxp9HzWMCMKaIqdXE+4STZz8/FAE8e3yuEbsXs/pmEtR0MZa8pBwmOvN5CSvG
u/zTgENjjv+UNmNeRA==
=IEGB
-----END PGP PUBLIC KEY BLOCK-----
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE4I1aChuaH07AdH+adlTpHiRAJW0FAmZPDqQACgkQdlTpHiRA
JW3pCg/+IrFuZCPP1UDf4/wxKAwS3FK4nWZx41zzCtNKDMqIdkT5yUAoAPpwRIrv
Tjpnf4zlUkH8kMyLwPMgfcTkg73LxmbwpMBPmClkf+Eo4NrB2heWY+1+jvEeaVwj
eWD0x16/3n0ZMr5y9nL3xKJkwjyfdkUOxpAemVbeZRFHkXALhoxH0Xpu0pF9tOPA
bw4Jkho7ofj9ytpFqyNFZpGHgL7VJDC1arcMcTXzcLLA5clbdFNQv+NEyCJdrtyq
/rbf6ZKPXLo0Td4axu7bWS5AoMwwWU+Q9yUUdNOy7hcJ9fxsKtVDjdFX1JLzCITw
xp2Dw127SIpqAARZm/zx6K09GgkeorcYi0YdrQEMU0tGZWlgNBY1lT4/0M+9dMtI
JxdwJC+48MHrQ4MmpW+rTdO0Vhvz6pC78epqe89IT19oYP/0oui69WNwNFeLeDKT
P1Rf1JkGTJoGhif9ibRkQ1mP/xwAv2qn0zeEpGYCwdYnDYISuikRDIYCipfYzGil
ZrjgqzZwXume0OI12Wcl9x6p4ueE0rj6iZ6MPQjMEAppP5mxWAt2ImaG+CDAzwAa
ja+Q59SrbVwi9GJP4AgvzCuyT3T+tQa0N9IvFTwLmoTplgg5LwglFJFeE+/Ko29v
Hqj/kO+ozUa6UMoGlcu2hJS4qa/ljaeY8n4UB+ZX2BScxDgMNU4=
=BRbR
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6663-3
May 23, 2024

openssl update
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS

Summary:

Add implicit rejection in PKCS#1 v1.5 in OpenSSL.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

USN-6663-1 provided a security update for OpenSSL.
This update provides the corresponding update for
Ubuntu 24.04 LTS.

Original advisory details:

 As a security improvement, OpenSSL will now
 return deterministic random bytes instead of an error
 when detecting wrong padding in PKCS#1 v1.5 RSA
 to prevent its use in possible Bleichenbacher timing attacks.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  libssl-doc                      3.0.13-0ubuntu3.1
  libssl3t64                      3.0.13-0ubuntu3.1
  openssl                         3.0.13-0ubuntu3.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6663-3
  https://ubuntu.com/security/notices/USN-6663-1
  https://launchpad.net/bugs/2054090

Package Information:
  https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.1

No comments:

Post a Comment