RHSA-2023:1335: Important: openssl security update
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Security Fix(es): openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1335?
The severity of RHSA-2023:1335 is classified as critical due to a potential address type confusion vulnerability.
How do I fix RHSA-2023:1335?
To fix RHSA-2023:1335, you should update your OpenSSL packages to version 1.0.2k-26.el7_9.
What components are affected by RHSA-2023:1335?
RHSA-2023:1335 affects multiple OpenSSL packages including openssl, openssl-libs, openssl-devel, and others.
What is CVE-2023-0286 in relation to RHSA-2023:1335?
CVE-2023-0286 refers to the specific vulnerability fixed in RHSA-2023:1335, which involves address type confusion in X.509 GeneralName.
When was RHSA-2023:1335 released?
RHSA-2023:1335 was released on the date specified in the Red Hat advisory, addressing critical security concerns.