Bugs fixes in "openssl"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2025-69421 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL ... | 2026-01-27 |
| CVE | CVE-2025-69420 | Issue summary: A type confusion vulnerability exists in the TimeStamp ... | 2026-01-27 |
| CVE | CVE-2025-69419 | Issue summary: Calling PKCS12_get_friendlyname() function on a malicio ... | 2026-01-27 |
| CVE | CVE-2025-69418 | Issue summary: When using the low-level OCB API directly with AES-NI o ... | 2026-01-27 |
| CVE | CVE-2025-68160 | Issue summary: Writing large, newline-free data into a BIO chain using ... | 2026-01-27 |
| CVE | CVE-2025-15467 | Issue summary: Parsing CMS AuthEnvelopedData message with maliciously ... | 2026-01-27 |
| CVE | CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | 2025-09-30 |
| CVE | CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | 2025-09-30 |
| CVE | CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | 2025-09-30 |
| CVE | CVE-2025-9231 | Timing side-channel in SM2 algorithm on 64 bit ARM | 2025-09-30 |
| CVE | CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | 2025-09-30 |
| CVE | CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | 2025-09-30 |
| CVE | CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | 2025-09-30 |
| CVE | CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | 2025-09-30 |
| CVE | CVE-2025-9231 | Timing side-channel in SM2 algorithm on 64 bit ARM | 2025-09-30 |
| CVE | CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | 2025-09-30 |
| CVE | CVE-2024-13176 | Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summ | 2025-02-21 |
| CVE | CVE-2024-9143 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds mem | 2025-02-21 |
| CVE | CVE-2024-13176 | Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summ | 2025-02-21 |
| CVE | CVE-2024-9143 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds mem | 2025-02-21 |
About
-
Send Feedback to @ubuntu_updates