Summary: | <dev-libs/openssl-{1.1.1r, 3.0.6}: NULL encryption with custom cipher with NID_undef | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | ajak, base-system, sam |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.openssl.org/news/secadv/20221011.txt | ||
Whiteboard: | A4 [glsa+] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() commit f99733502c417e043f89f01042abec3b854d203c (origin/master, origin/HEAD) Author: Patrick McLean <chutzpah@gentoo.org> Date: Tue Oct 11 15:59:14 2022 -0700 dev-libs/openssl: add 3.0.6 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> commit 6e33789090395e63bac19f152782c3b85f5ed1b4 Author: Patrick McLean <chutzpah@gentoo.org> Date: Tue Oct 11 15:53:12 2022 -0700 dev-libs/openssl: add 1.1.1r Signed-off-by: Patrick McLean <chutzpah@gentoo.org> commit 17e29d72ab7d349ac79c15291d47eb1a8499265b Author: Sam James <sam@gentoo.org> Date: Thu Oct 13 00:40:05 2022 +0100 dev-libs/openssl: drop yanked, masked versions Especially important given many will be unmasking 3.x generally. Signed-off-by: Sam James <sam@gentoo.org> commit 9163b1239929bfe249d49bb24e5ccb13c27d683e Author: Sam James <sam@gentoo.org> Date: Wed Oct 12 18:28:59 2022 +0100 profiles: add link to openssl regression/bug Bug: https://github.com/openssl/openssl/issues/19389 Signed-off-by: Sam James <sam@gentoo.org> commit ea4f4da1ba175ad6e07c74d27429c0d037f41f0c Author: Sam James <sam@gentoo.org> Date: Wed Oct 12 15:40:10 2022 +0100 profiles: mask "withdrawn" openssls with a "significant regression" Upstream has withdrawn these releases because of a (yet unexplained) "significant regression". See https://mta.openssl.org/pipermail/openssl-announce/2022-October/000237.html. Signed-off-by: Sam James <sam@gentoo.org> GLSA request filed, though we're still waiting for fixed versions here. If it takes a while we can just drop it from the GLSA if necessary. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=9db8cdf286ccec973fe12c1ebbb6ac75afd7e305 commit 9db8cdf286ccec973fe12c1ebbb6ac75afd7e305 Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2022-10-16 14:31:06 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-10-16 14:39:36 +0000 [ GLSA 202210-02 ] Drop bug 876787, unfixed Bug: https://bugs.gentoo.org/876787 Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202210-02.xml | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) https://gitweb.gentoo.org/data/glsa.git/commit/?id=143e8d174e14e346f2c37e8a31a4be211ac3e24c commit 143e8d174e14e346f2c37e8a31a4be211ac3e24c Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-10-16 14:27:07 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-10-16 14:39:36 +0000 [ GLSA 202210-02 ] OpenSSL: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/741570 Bug: https://bugs.gentoo.org/809980 Bug: https://bugs.gentoo.org/832339 Bug: https://bugs.gentoo.org/835343 Bug: https://bugs.gentoo.org/842489 Bug: https://bugs.gentoo.org/856592 Bug: https://bugs.gentoo.org/876787 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202210-02.xml | 56 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 56 insertions(+) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=530086715f82de12009538347725dbfd14e6b0a8 commit 530086715f82de12009538347725dbfd14e6b0a8 Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2022-10-14 03:47:09 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-10-16 14:52:19 +0000 profiles: mask <openssl-1.1.1 Bug: https://bugs.gentoo.org/876787 Bug: https://bugs.gentoo.org/741570 Bug: https://bugs.gentoo.org/809980 Bug: https://bugs.gentoo.org/832339 Bug: https://bugs.gentoo.org/835343 Bug: https://bugs.gentoo.org/842489 Bug: https://bugs.gentoo.org/856592 Closes: https://github.com/gentoo/gentoo/pull/22909 Signed-off-by: John Helmert III <ajak@gentoo.org> profiles/package.mask | 5 +++++ 1 file changed, 5 insertions(+) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=f353a9a7c6ffd4dd54f9b93774d103942a88892e commit f353a9a7c6ffd4dd54f9b93774d103942a88892e Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-02-04 08:02:53 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-02-04 08:03:15 +0000 [ GLSA 202402-08 ] OpenSSL: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/876787 Bug: https://bugs.gentoo.org/893446 Bug: https://bugs.gentoo.org/902779 Bug: https://bugs.gentoo.org/903545 Bug: https://bugs.gentoo.org/907413 Bug: https://bugs.gentoo.org/910556 Bug: https://bugs.gentoo.org/911560 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202402-08.xml | 63 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) |