[SECURITY] [DSA 4475-1] openssl security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.comp.security.bugtraq
Message-ID <20190701211244.ycmyqtxsg4wfq7hh__31960.6500955828$1562034884$gmane$org@seger.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4475-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
July 01, 2019                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : openssl
CVE ID         : CVE-2019-1543

Joran Dirk Greef discovered that overly long nonces used with
ChaCha20-Poly1305 were incorrectly processed and could result in nonce
reuse. This doesn't affect OpenSSL-internal uses of ChaCha20-Poly1305
such as TLS.

For the stable distribution (stretch), this problem has been fixed in
version 1.1.0k-1~deb9u1. This DSA also upgrades openssl1.0 (which
itself is not affected by CVE-2019-1543) to 1.0.2s-1~deb9u1

We recommend that you upgrade your openssl packages.

For the detailed security status of openssl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openssl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl0adR4ACgkQEMKTtsN8
Tjbh4RAArq1enTQE05VZeU6jPVXsMcZXUbFlGrMysFqUvGiR9UZaOwbFYhtmXKH9
4sjCGFRJXpyHkY2P33r6G+NmGEimD24ZdcLZnnZzO5y3uPpNsGvmBZwROt63E3zM
jXCigJAFSoJV5wctIZmD0HsaIJng1VlYXEkLI9UKA+xLYaklSFB8hSQsxeDbgazv
TqFjFJa6e7l2B81LRBC4bs0X5VmXrZKOrKcteGvSRVdtQsPnimjaEmtWVjVdzYAm
zGbEBOVckTiaYVrk9qTXHX4o4NUGuZlssLPTMK636ypMriN/Idd8g5wQFgEzYUGm
0efOFIvOIQh/ziOndA3GeWNrb7LM9Nb8viGtkRw6LoNvcjsSFNeiH36MPhc2wcqZ
HuO6UgIHmbmNFWucTCrmHdIitYJI9IJRDPOtG4lCO9AXbrZR+jRup2Q4+XYx937H
cF18bjgfIKUJ9FcKX3X/knsgfhxkFzFORycarE7lLWafr/8SxnxbZGGDyK00hTym
bQIpp/H9kOIR0dFXlahwkHMQl4b8SA1kUqf6Ts+3KceaCSQ7GilGJ6eZob1/CyQo
1xmRJvi28fwbyeuQDxtmXm/HcjkPnucYN47lwWNIE/sjmdTnstbImz4ehUuMRrkf
PQjhjhBgorRGcZbcqGyMfnZAr/Y9m+6pzXjdprSu8ZsfP1ATrKw=
=tnxv
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.