jambonz / jambonz-infrastructure

packer and cloudformation templates for creating EC2-based jambonz deployments
23 stars 30 forks source link

Need Fix For OpenSSL (1.1.1n-0+deb11u5) Bug for Debian 11 or upgrade to latest OS #71

Open nitinpo-Kore opened 1 year ago

nitinpo-Kore commented 1 year ago

JAMBONZ Authenticated Vulnerability Scan_15Aug23_8pm.zip

@davehorton kindly find the attached VA SCAN Report ,password share in personal. Also i have done some research and found that nessus is not getting full version of debian which is 1.1.1n-0+deb11u5 therefore giving more vulnerability, i am checking that internally. But we have two CVE-2023-3446 & CVE-2023-3817 which are related to medium bug and i have found its there in bookworm also when debian team will solve it no idea. https://security-tracker.debian.org/tracker/CVE-2023-3446 & https://security-tracker.debian.org/tracker/CVE-2023-3817 image You can refer below for more reference : https://tracker.debian.org/pkg/openssl https://security-tracker.debian.org/tracker/source-package/openssl So please help closing these.