Advisories for package 'openssl-src'
-
RUSTSEC-2023-0006: Vulnerability in openssl-src
X.400 address type confusion in X.509
GeneralName
-
RUSTSEC-2023-0010: Vulnerability in openssl-src
Double free after calling
PEM_read_bio_ex
-
RUSTSEC-2023-0007: Vulnerability in openssl-src
Timing Oracle in RSA Decryption
-
RUSTSEC-2023-0013: Vulnerability in openssl-src
NULL
dereference during PKCS7 data verification -
RUSTSEC-2023-0008: Vulnerability in openssl-src
X.509 Name Constraints Read Buffer Overflow
-
RUSTSEC-2023-0009: Vulnerability in openssl-src
Use-after-free following
BIO_new_NDEF
-
RUSTSEC-2023-0011: Vulnerability in openssl-src
Invalid pointer dereference in
d2i_PKCS7
functions -
RUSTSEC-2023-0012: Vulnerability in openssl-src
NULL
dereference validating DSA public key -
RUSTSEC-2022-0065: Vulnerability in openssl-src
X.509 Email Address Variable Length Buffer Overflow
-
RUSTSEC-2022-0064: Vulnerability in openssl-src
X.509 Email Address 4-byte Buffer Overflow
-
RUSTSEC-2022-0059: Vulnerability in openssl-src
Using a Custom Cipher with
NID_undef
may lead to NULL encryption -
RUSTSEC-2022-0032: Vulnerability in openssl-src
AES OCB fails to encrypt some bytes
-
RUSTSEC-2022-0033: Vulnerability in openssl-src
Heap memory corruption with RSA private key operation
-
MEDIUM RUSTSEC-2022-0027: Vulnerability in openssl-src
OCSP_basic_verify
may incorrectly verify the response signing certificate -
MEDIUM RUSTSEC-2022-0026: Vulnerability in openssl-src
Incorrect MAC key used in the RC4-MD5 ciphersuite
-
HIGH RUSTSEC-2022-0025: Vulnerability in openssl-src
Resource leakage when decoding certificates and keys
-
RUSTSEC-2022-0014: Vulnerability in openssl-src
Infinite loop in
BN_mod_sqrt()
reachable when parsing certificates -
RUSTSEC-2021-0129: Vulnerability in openssl-src
Invalid handling of
X509_verify_cert()
internal errors in libssl -
HIGH RUSTSEC-2021-0098: Vulnerability in openssl-src
Read buffer overruns processing ASN.1 strings
-
CRITICAL RUSTSEC-2021-0097: Vulnerability in openssl-src
SM2 Decryption Buffer Overflow
-
MEDIUM RUSTSEC-2021-0055: Vulnerability in openssl-src
NULL pointer deref in signature_algorithms processing
-
HIGH RUSTSEC-2021-0056: Vulnerability in openssl-src
CA certificate check bypass with X509_V_FLAG_X509_STRICT
-
MEDIUM RUSTSEC-2021-0058: Vulnerability in openssl-src
Null pointer deref in
X509_issuer_and_serial_hash()
-
HIGH RUSTSEC-2021-0057: Vulnerability in openssl-src
Integer overflow in CipherUpdate
-
HIGH RUSTSEC-2020-0015: Vulnerability in openssl-src
Crash causing Denial of Service attack