sonic-net / sonic-fips

SONiC FIPS module
Other
0 stars 9 forks source link

Upgrade OpenSSL from 1.1.1n-0+deb11u4 to 1.1.1n-0+deb11u6 #44

Closed xumia closed 4 months ago

xumia commented 11 months ago

Upgrade OpenSSL to 1.1.1n-0+deb11u6

Remove some of the patches already added in debian/patches. Fix CVEs: CVE-2023-0464 (Excessive Resource Usage Verifying X.509 Policy CVE-2023-0465 (Invalid certificate policies in leaf certificates are CVE-2023-0466 (Certificate policy check not enabled). CVE-2022-4304 (Timing Oracle in RSA Decryption). CVE-2023-2650 (Possible DoS translating ASN.1 object identifiers).