David Benjamin discovered that OpenSSL incorrectly handled X.400 address processing. A remote attacker could possibly use this issue to read arbitrary memory contents or cause OpenSSL to crash, resulting in a denial of service. (CVE-2023-0286)
Octavio Galland and Marcel Böhme discovered that OpenSSL incorrectly handled streaming ASN.1 data. A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-0215)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.0.2n-1ubuntu5.11", "binary_name": "libcrypto1.0.0-udeb" }, { "binary_version": "1.0.2n-1ubuntu5.11", "binary_name": "libssl1.0-dev" }, { "binary_version": "1.0.2n-1ubuntu5.11", "binary_name": "libssl1.0.0" }, { "binary_version": "1.0.2n-1ubuntu5.11", "binary_name": "libssl1.0.0-dbgsym" }, { "binary_version": "1.0.2n-1ubuntu5.11", "binary_name": "libssl1.0.0-udeb" }, { "binary_version": "1.0.2n-1ubuntu5.11", "binary_name": "openssl1.0" }, { "binary_version": "1.0.2n-1ubuntu5.11", "binary_name": "openssl1.0-dbgsym" } ] }