Your message dated Sun, 27 Oct 2024 16:49:39 +0000
with message-id <[email protected]>
and subject line Bug#1085378: fixed in openssl 3.3.2-2
has caused the Debian Bug report #1085378,
regarding openssl: CVE-2024-9143
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1085378: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1085378
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: openssl
X-Debbugs-CC: [email protected]
Severity: normal
Tags: security
Hi,
The following vulnerability was published for openssl.
CVE-2024-9143[0]:
| Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with
| untrusted explicit values for the field polynomial can lead to out-
| of-bounds memory reads or writes. Impact summary: Out of bound
| memory writes can lead to an application crash or even a possibility
| of a remote code execution, however, in all the protocols involving
| Elliptic Curve Cryptography that we're aware of, either only "named
| curves" are supported, or, if explicit curve parameters are
| supported, they specify an X9.62 encoding of binary (GF(2^m)) curves
| that can't represent problematic input values. Thus the likelihood
| of existence of a vulnerable application is low. In particular, the
| X9.62 encoding is used for ECC keys in X.509 certificates, so
| problematic inputs cannot occur in the context of processing X.509
| certificates. Any problematic use-cases would have to be using an
| "exotic" curve encoding. The affected APIs include:
| EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(), and various
| supporting BN_GF2m_*() functions. Applications working with
| "exotic" explicit binary (GF(2^m)) curve parameters, that make it
| possible to represent invalid field polynomials with a zero constant
| term, via the above or similar APIs, may terminate abruptly as a
| result of reading or writing outside of array bounds. Remote code
| execution cannot easily be ruled out. The FIPS modules in 3.3, 3.2,
| 3.1 and 3.0 are not affected by this issue.
https://openssl-library.org/news/secadv/20241016.txt
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-9143
https://www.cve.org/CVERecord?id=CVE-2024-9143
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: openssl
Source-Version: 3.3.2-2
Done: Sebastian Andrzej Siewior <[email protected]>
We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <[email protected]> (supplier of updated
openssl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 27 Oct 2024 15:19:50 +0100
Source: openssl
Architecture: source
Version: 3.3.2-2
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSL Team <[email protected]>
Changed-By: Sebastian Andrzej Siewior <[email protected]>
Closes: 1085378
Changes:
openssl (3.3.2-2) unstable; urgency=medium
.
- CVE-2024-9143 (Low-level invalid GF(2^m) parameters lead to OOB memory
access) (Closes: #1085378).
Checksums-Sha1:
abd953674b3c430b6f2855286e5f05ace45c3b24 2808 openssl_3.3.2-2.dsc
55b81f38305d8cfe81d2dd48a143dfcd3aafe265 52228 openssl_3.3.2-2.debian.tar.xz
Checksums-Sha256:
4a2d357c049c5f0da96fb9615e6ddbfface5a71de1dfa8a95120a251d1a3105d 2808
openssl_3.3.2-2.dsc
d5d0c7c5a35e10b580b016866a75a454da3b477f90516501fa1861989befc33b 52228
openssl_3.3.2-2.debian.tar.xz
Files:
f19f251cc3800079de06f41e99d76cd3 2808 utils optional openssl_3.3.2-2.dsc
5acf52f6452f3aca8f26a77f737f17ae 52228 utils optional
openssl_3.3.2-2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEZCVGlf/wqkRmzBnme5boFiqM9dEFAmceba8ACgkQe5boFiqM
9dHi1A//YSJtS6PJUJMRrOM1DPV/0T+/P/3GR2H9Tk+sbKnR5Apw2WxiZf6kRh0c
JzB4bNlQRFpBKxJE24Hl5OrLEx8qTJdNAmGlBkBij/3JizKubhV73Q5PlmZ7nle4
rtjKJiuDMfmnl7K5l6By7nTAixg4kmfrSNpSaNYieAh92S38c6z2cw5TfXX1GS41
maiyMbwO09gvFwScC/T+Zvwm0M2BVSgYqiTniXoXKNivrsa5WqLoZg8p4opZOA01
09LzuiQqwad+Iu3NkAfTK6b4C0LsmPnJAfYdutPEXNkYQev5EOn6/JRGPBNc0Unx
10N7wEPnlhGpGff7DuQ6QTE0GXAhpVX0lKuzzls10ZflQU39g9K2Z3IogK1Mcm1i
ivrpcGQpxu7OYAsomD5jjo2fNPXBhkoaWjtGHcB8DebRI7fIJZFRcaEGdNq/0lIk
FUF//hq9FYtSzs9eJraSUaH0vjFWSlTDMpXpQiBJzMUgJEEG/ZPCXMLJEqb0q6Bk
s7mIM7CxrO/WwxYfxogM9P/EZKBA12qRC64lcCtsmXPkQexeoEwBGRVZjc2by+81
cWcKGKOsDpbWMxrZb8IsZwOgaBvgqhbV1fbncItLiTWK71B4EVfOcwT6PwxOWff6
syel5sQA+9lAuuQADdDueY6zDkJcZMmAjCBpr/+0vYP2IeBD81g=
=7AGX
-----END PGP SIGNATURE-----
pgp1LsVnFMVKH.pgp
Description: PGP signature
--- End Message ---