Vulnerability Database
Blog
FAQ
Docs
RHSA-2024:2447
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2024:2447
Import Source
https://security.access.redhat.com/data/osv/RHSA-2024:2447.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2024:2447
Related
CVE-2023-2975
CVE-2023-3446
CVE-2023-3817
CVE-2023-5678
CVE-2023-6129
CVE-2023-6237
CVE-2024-0727
Published
2024-09-16T15:56:03Z
Modified
2024-10-30T00:07:27Z
Severity
6.5 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: openssl and openssl-fips-provider security update
Details
References
https://access.redhat.com/errata/RHSA-2024:2447
https://access.redhat.com/security/updates/classification/#low
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.4_release_notes/index
https://bugzilla.redhat.com/show_bug.cgi?id=2223016
https://bugzilla.redhat.com/show_bug.cgi?id=2224962
https://bugzilla.redhat.com/show_bug.cgi?id=2227852
https://bugzilla.redhat.com/show_bug.cgi?id=2248616
https://bugzilla.redhat.com/show_bug.cgi?id=2257571
https://bugzilla.redhat.com/show_bug.cgi?id=2258502
https://bugzilla.redhat.com/show_bug.cgi?id=2259944
https://issues.redhat.com/browse/RHEL-14083
https://issues.redhat.com/browse/RHEL-15990
https://issues.redhat.com/browse/RHEL-17104
https://issues.redhat.com/browse/RHEL-17193
https://issues.redhat.com/browse/RHEL-1780
https://issues.redhat.com/browse/RHEL-20249
https://issues.redhat.com/browse/RHEL-5295
https://issues.redhat.com/browse/RHEL-5304
https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2447.json
https://access.redhat.com/security/cve/CVE-2023-2975
https://www.cve.org/CVERecord?id=CVE-2023-2975
https://nvd.nist.gov/vuln/detail/CVE-2023-2975
https://www.openssl.org/news/secadv/20230714.txt
https://access.redhat.com/security/cve/CVE-2023-3446
https://www.cve.org/CVERecord?id=CVE-2023-3446
https://nvd.nist.gov/vuln/detail/CVE-2023-3446
https://www.openssl.org/news/secadv/20230719.txt
https://access.redhat.com/security/cve/CVE-2023-3817
https://www.cve.org/CVERecord?id=CVE-2023-3817
https://nvd.nist.gov/vuln/detail/CVE-2023-3817
https://www.openssl.org/news/secadv/20230731.txt
https://access.redhat.com/security/cve/CVE-2023-5678
https://www.cve.org/CVERecord?id=CVE-2023-5678
https://nvd.nist.gov/vuln/detail/CVE-2023-5678
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6
https://www.openssl.org/news/secadv/20231106.txt
https://access.redhat.com/security/cve/CVE-2023-6129
https://www.cve.org/CVERecord?id=CVE-2023-6129
https://nvd.nist.gov/vuln/detail/CVE-2023-6129
https://www.openssl.org/news/secadv/20240109.txt
https://www.openwall.com/lists/oss-security/2024/01/09/1
https://access.redhat.com/security/cve/CVE-2023-6237
https://www.cve.org/CVERecord?id=CVE-2023-6237
https://nvd.nist.gov/vuln/detail/CVE-2023-6237
https://www.openssl.org/news/secadv/20240115.txt
https://www.openwall.com/lists/oss-security/2024/01/15/2
https://access.redhat.com/security/cve/CVE-2024-0727
https://www.cve.org/CVERecord?id=CVE-2024-0727
https://nvd.nist.gov/vuln/detail/CVE-2024-0727
https://github.com/openssl/openssl/pull/23362
https://www.openssl.org/news/secadv/20240125.txt
Affected packages
Red Hat:enterprise_linux:9::appstream
/
openssl
Package
Name
openssl
Purl
pkg:rpm/redhat/openssl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::appstream
/
openssl-debuginfo
Package
Name
openssl-debuginfo
Purl
pkg:rpm/redhat/openssl-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::appstream
/
openssl-debugsource
Package
Name
openssl-debugsource
Purl
pkg:rpm/redhat/openssl-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::appstream
/
openssl-devel
Package
Name
openssl-devel
Purl
pkg:rpm/redhat/openssl-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::appstream
/
openssl-libs
Package
Name
openssl-libs
Purl
pkg:rpm/redhat/openssl-libs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::appstream
/
openssl-libs-debuginfo
Package
Name
openssl-libs-debuginfo
Purl
pkg:rpm/redhat/openssl-libs-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::appstream
/
openssl-perl
Package
Name
openssl-perl
Purl
pkg:rpm/redhat/openssl-perl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::baseos
/
openssl
Package
Name
openssl
Purl
pkg:rpm/redhat/openssl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::baseos
/
openssl-debuginfo
Package
Name
openssl-debuginfo
Purl
pkg:rpm/redhat/openssl-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::baseos
/
openssl-debugsource
Package
Name
openssl-debugsource
Purl
pkg:rpm/redhat/openssl-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::baseos
/
openssl-devel
Package
Name
openssl-devel
Purl
pkg:rpm/redhat/openssl-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::baseos
/
openssl-libs
Package
Name
openssl-libs
Purl
pkg:rpm/redhat/openssl-libs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::baseos
/
openssl-libs-debuginfo
Package
Name
openssl-libs-debuginfo
Purl
pkg:rpm/redhat/openssl-libs-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
Red Hat:enterprise_linux:9::baseos
/
openssl-perl
Package
Name
openssl-perl
Purl
pkg:rpm/redhat/openssl-perl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.0.7-27.el9
RHSA-2024:2447 - OSV