USN-6663-3

See a problem?
Source
https://ubuntu.com/security/notices/USN-6663-3
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6663-3.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6663-3
Related
Published
2024-05-23T09:27:17.194097Z
Modified
2024-05-23T09:27:17.194097Z
Summary
openssl update
Details

USN-6663-1 provided a security update for OpenSSL. This update provides the corresponding update for Ubuntu 24.04 LTS.

Original advisory details:

As a security improvement, OpenSSL will now return deterministic random bytes instead of an error when detecting wrong padding in PKCS#1 v1.5 RSA to prevent its use in possible Bleichenbacher timing attacks.

References

Affected packages

Ubuntu:24.04:LTS / openssl

Package

Name
openssl
Purl
pkg:deb/ubuntu/openssl?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.13-0ubuntu3.1

Affected versions

3.*

3.0.10-1ubuntu2
3.0.10-1ubuntu2.1
3.0.10-1ubuntu3
3.0.10-1ubuntu4
3.0.13-0ubuntu2
3.0.13-0ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.0.13-0ubuntu3.1",
            "binary_name": "libssl-dev"
        },
        {
            "binary_version": "3.0.13-0ubuntu3.1",
            "binary_name": "libssl-doc"
        },
        {
            "binary_version": "3.0.13-0ubuntu3.1",
            "binary_name": "libssl3t64"
        },
        {
            "binary_version": "3.0.13-0ubuntu3.1",
            "binary_name": "libssl3t64-dbgsym"
        },
        {
            "binary_version": "3.0.13-0ubuntu3.1",
            "binary_name": "openssl"
        },
        {
            "binary_version": "3.0.13-0ubuntu3.1",
            "binary_name": "openssl-dbgsym"
        }
    ]
}