Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport release-21.11] openssl_3_0: 3.0.2 -> 3.0.3 #171501

Merged
merged 1 commit into from
May 5, 2022

Conversation

github-actions[bot]
Copy link
Contributor

@github-actions github-actions bot commented May 4, 2022

Bot-based backport to release-21.11, triggered by a label in #171491.

  • Before merging, ensure that this backport complies with the Criteria for Backporting.
    • Even as a non-commiter, if you find that it does not comply, leave a comment.

- The c_rehash script allows command injection (CVE-2022-1292)
- OCSP_basic_verify may incorrectly verify the response signing
  certificate (CVE-2022-1343)
- Incorrect MAC key used in the RC4-MD5 ciphersuite (CVE-2022-1434)
- Resource leakage when decoding certificates and keys (CVE-2022-1473)

https://mta.openssl.org/pipermail/openssl-announce/2022-May/000224.html

Fixes: CVE-2022-1292, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473
(cherry picked from commit c62eceb)
@github-actions github-actions bot requested a review from jonringer as a code owner May 4, 2022 07:24
@github-actions github-actions bot mentioned this pull request May 4, 2022
13 tasks
@mweinelt mweinelt added the 1.severity: security Issues which raise a security issue, or PRs that fix one label May 4, 2022
@mweinelt mweinelt requested a review from ajs124 May 4, 2022 23:14
@vcunat vcunat merged commit 3623de8 into release-21.11 May 5, 2022
@ajs124 ajs124 deleted the backport-171491-to-release-21.11 branch May 5, 2022 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1.severity: security Issues which raise a security issue, or PRs that fix one 10.rebuild-darwin: 1-10 10.rebuild-linux: 1-10
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants