Debian Security Advisory
DLA-2952-1 openssl -- LTS security update
- Date Reported:
- 17 Mar 2022
- Affected Packages:
- openssl
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2019-1551, CVE-2022-0778.
- More information:
-
Tavis Ormandy discovered that the BN_mod_sqrt() function of OpenSSL could be tricked into an infinite loop. This could result in denial of service via malformed certificates.
In addition, this update fixes an overflow bug in the x64_64 Montgomery squaring procedure.
For Debian 9 stretch, these problems have been fixed in version 1.1.0l-1~deb9u5.
We recommend that you upgrade your openssl packages.
For the detailed security status of openssl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openssl
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS