ELA-1258-1 openssl security update

multiple vulnerabilities

2024-11-30
Packageopenssl
Version1.0.1t-1+deb8u22 (jessie)
Related CVEs CVE-2023-5678 CVE-2024-0727


Multiple vulnerabilities were discovered in OpenSSL, the Secure Sockets Layer toolkit.

CVE-2023-5678

A denial of service could occur with excessively long X9.42 DH keys.

CVE-2024-0727

A denial of service could occur with a null field in a PKCS12 file.



For Debian 8 jessie, these problems have been fixed in version 1.0.1t-1+deb8u22.

We recommend that you upgrade your openssl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.