[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4176-1] openssl security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4176-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Adrian Bunk
May 24, 2025                                  https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : openssl
Version        : 1.1.1w-0+deb11u3
CVE ID         : CVE-2024-13176
Debian Bug     : 1094027

A timing side-channel in ECDSA signature computation has been fixed in 
the cryptography library OpenSSL.

For Debian 11 bullseye, this problem has been fixed in version
1.1.1w-0+deb11u3.

We recommend that you upgrade your openssl packages.

For the detailed security status of openssl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openssl

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmgyK7cACgkQiNJCh6LY
mLFRmQ//QEgysZ+AsTjT4t1++lpYsC5b5H6PHCB02utGCiKm9STgUD9trGqEDAF1
NpWwngTOsxkFnf0z1m1ry+zxotjx9ERZ4yTJu66A1Th4PvX3j3+oyXFegsgb54/M
gfRcDExrmg8bOGABj9yvJ250B9VvCVZO9UOnLKe/ddFULMoc9Bpo+xHZgLkrwT7z
ZxKs9cqtqUMyReYTBjmmaxNT+fUPDzoHPEVvMRb4qDakTSYI8mYuc47TMLEl4a4N
W5qgIYrqT1wo0fSk7/32qEglkYb/1G2PV0QH55z8ev9KguqOW26OX4MPdYEaeRM2
+id2dD8Tzo3AjAFX9Xrw4nhv5cjdzIn9AcbjY2K/FYj71Ljw0sbEgd+u8x060xuz
lMYNoCNGL/y9+16B/W9aw4iooLoK++gRlsv8f/y2qGE+pS1WUOZN9czadNDAk93s
TykUhTGMnBiGcbaKAffWG7YgJ4Gq46tStnX3wRKSu71AY1FayLyZNNKj+aJa90U9
H1ljgQyg3GJ3Vh/RDD1ULI6ld7u7PRE4XQK7Ck9m7qt/nP4RuwPdVKjQpRdD9uD5
Ee0jaCrpYbkFmth+yNbKYizWo5bNj3ke6yqw7rIHLuYCHR+MYHq96aME1mJbMWr2
x53v1UPdu5pESaoc061An8dxmgNvkI0JC62BUM/FJuDg6va/C3E=
=v1T1
-----END PGP SIGNATURE-----


Reply to: