Looking only at the upstream version number is not enough to determine if the 
package is vulnerable. Fixes usually get backported individually without 
bumping to a newer upstream release.
Check out the changelog at 
https://git.launchpad.net/ubuntu/+source/openssl/tree/debian/changelog?h=ubuntu/noble-security
 and you will see that it includes a CVE fix for the issue you mentioned and a 
lot more.

If you want to verify whether a specific CVE was fixed in our packages
you can also take a look at
https://ubuntu.com/security/notices?details=openssl

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2125752

Title:
  OpenSSL package in Ubuntu 24.04 needs updating

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2125752/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to