Your message dated Thu, 31 Oct 2024 21:18:23 +0000
with message-id <[email protected]>
and subject line Bug#1085378: fixed in openssl 3.0.15-1~deb12u1
has caused the Debian Bug report #1085378,
regarding openssl: CVE-2024-9143
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1085378: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1085378
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: openssl
X-Debbugs-CC: [email protected]
Severity: normal
Tags: security
Hi,
The following vulnerability was published for openssl.
CVE-2024-9143[0]:
| Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with
| untrusted explicit values for the field polynomial can lead to out-
| of-bounds memory reads or writes. Impact summary: Out of bound
| memory writes can lead to an application crash or even a possibility
| of a remote code execution, however, in all the protocols involving
| Elliptic Curve Cryptography that we're aware of, either only "named
| curves" are supported, or, if explicit curve parameters are
| supported, they specify an X9.62 encoding of binary (GF(2^m)) curves
| that can't represent problematic input values. Thus the likelihood
| of existence of a vulnerable application is low. In particular, the
| X9.62 encoding is used for ECC keys in X.509 certificates, so
| problematic inputs cannot occur in the context of processing X.509
| certificates. Any problematic use-cases would have to be using an
| "exotic" curve encoding. The affected APIs include:
| EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(), and various
| supporting BN_GF2m_*() functions. Applications working with
| "exotic" explicit binary (GF(2^m)) curve parameters, that make it
| possible to represent invalid field polynomials with a zero constant
| term, via the above or similar APIs, may terminate abruptly as a
| result of reading or writing outside of array bounds. Remote code
| execution cannot easily be ruled out. The FIPS modules in 3.3, 3.2,
| 3.1 and 3.0 are not affected by this issue.
https://openssl-library.org/news/secadv/20241016.txt
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-9143
https://www.cve.org/CVERecord?id=CVE-2024-9143
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: openssl
Source-Version: 3.0.15-1~deb12u1
Done: Sebastian Andrzej Siewior <[email protected]>
We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <[email protected]> (supplier of updated
openssl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 27 Oct 2024 15:16:28 +0100
Source: openssl
Architecture: source
Version: 3.0.15-1~deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: Debian OpenSSL Team <[email protected]>
Changed-By: Sebastian Andrzej Siewior <[email protected]>
Closes: 1074487 1085378
Changes:
openssl (3.0.15-1~deb12u1) bookworm; urgency=medium
.
* Import 3.0.15
- CVE-2024-5535 (SSL_select_next_proto buffer overread)
(Closes: #1074487).
- CVE-2024-9143 (Low-level invalid GF(2^m) parameters lead to OOB memory
access) (Closes: #1085378).
Checksums-Sha1:
4d9249449834a193bae7531ff730d25f088a7752 2675 openssl_3.0.15-1~deb12u1.dsc
cecd647994de5b6bd065d88d8c81ad30f8ac6409 15318633 openssl_3.0.15.orig.tar.gz
1800c5c002de9d0a81dc7820178b1c96869de2aa 833 openssl_3.0.15.orig.tar.gz.asc
2aaa3f6f2406ff4fe8aa1b84b69d6e2b4cb3d9b1 55220
openssl_3.0.15-1~deb12u1.debian.tar.xz
Checksums-Sha256:
c036907f6c634ea026143b904f8359222dabe44ef756d13e124e7e7645ef0d67 2675
openssl_3.0.15-1~deb12u1.dsc
23c666d0edf20f14249b3d8f0368acaee9ab585b09e1de82107c66e1f3ec9533 15318633
openssl_3.0.15.orig.tar.gz
781ffd542b9ec58d88333abb9af7fb8133059703f023a0b1a555086c51b2b3de 833
openssl_3.0.15.orig.tar.gz.asc
c4428a53771dd15b8cb1de4a790fae23b849438bd59f853f2ac686eee7e38876 55220
openssl_3.0.15-1~deb12u1.debian.tar.xz
Files:
7888338acd0fa561c8f2847f53cf82e1 2675 utils optional
openssl_3.0.15-1~deb12u1.dsc
08f458c00fff496a52ef931c481045cd 15318633 utils optional
openssl_3.0.15.orig.tar.gz
ff2a0b40ee7d92996e6c4c8c412a3a57 833 utils optional
openssl_3.0.15.orig.tar.gz.asc
f6e19decabfc830fa7765f0b843a9c2f 55220 utils optional
openssl_3.0.15-1~deb12u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEZCVGlf/wqkRmzBnme5boFiqM9dEFAmcenCkACgkQe5boFiqM
9dEI5RAAtY1gpHf1+igXEGZYCHIHzBRYUgeSY7Fm+sg4AkPinurUK2QBj+grtlKN
Y+4Y0t1yyCH3PiuPwuuXTq64WdftuiscnGF2bNavJMx4e46Bjjjk11/rBgR/QNgh
yzrbuEpYbNGnk5wkIWXi8IUAEHqoHjUhY0E0++zTic8RMAjJYlSW9fPzRo8mvdIc
pw7M6kwWypCcJDEUdjAXqTGi5FW+xPsK/dBaAHjLWJHsX8tN/O+EAy+Hbj8//MGE
nAvZtoiWMr/49/5ISmQT8mbGfqwIuwYn+cb8qSG/+qnMvjBaNQK1wddBtXTxFe8A
UlqvxnvfxXFjb/qo1AVp4PIkr+ULwBU+YNbut8kbVsvhKTdycKhPqh7o+pG5wCyf
/l//dW5U2V+x3wDZmXBBeuLwsbAh/hOX3Y6KYFoHOoNE5nSjDoSMDuLtV+UnKCTP
qdDAy/ovX/HBPTfdEpbeTTMJQpwHw1RXtqGh0ZYlXRbDfNxNsW3eyG0E7m34MS6o
1Z9IxdMbCQIC2NVtjvEHIUB8ui6KKoRL/5S/oNSJFaBJBVjtGPDmTHrAbN3D2yHL
qS5oIypsT3kQPT3MbLy8qeV5Ep5jmrvJB3Ddbi3mZH5TG4ZNpy/y+0h4YcgNxzgm
/67nFr/jY1rjltGWiBSGbAQ2k4h8YBMQT55M3nIaqBjkA39IPxI=
=swOo
-----END PGP SIGNATURE-----
pgpxDtz0KDE2s.pgp
Description: PGP signature
--- End Message ---