[DSA 6015-1] openssl security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6015-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
October 01, 2025                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : openssl
CVE ID         : CVE-2025-9230 CVE-2025-9231 CVE-2025-9232

Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit, which may result in denial of service or
information leaks.

Additional details can be found in the upstream advisory:
https://openssl-library.org/news/secadv/20250930.txt

For the oldstable distribution (bookworm), these problems have been fixed
in version 3.0.17-1~deb12u3.

For the stable distribution (trixie), these problems have been fixed in
version 3.5.1-1+deb13u1.

We recommend that you upgrade your openssl packages.

For the detailed security status of openssl please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/openssl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmjdJlRfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0T0zA/8DDBPqsCWz4i/GuvqW9DbaQcuT6QojnLCcGjJvQydPzp50fhCUlHXIVhI
0HMLQUaD8m7GVpP2zrYrOV0KtLKRldaO9C9SBwsDuKgBaFiwalAin53gvNYzI39i
E+lffriMglwyTMnv48IK3r8wamlxqR2BhitY7RR+IXVAZoTc4lqvUEepWO16Lkqs
CpMnvhiqSSKj1hUpkuNfhadDFh+afbRpvV+OXSWGzXGReZC3jO8STaoEwX7AcZJA
ot0jKf++pFtf7r1xF0PV3Pf5WSJ6OBqeirkpFs+qrrIolbhFE5sYb7ha2VoT0dSB
MQin/yAndbm9R+yVppNOZUnTGQjD28sdF1ajnLDwcb0H1Hshj7j4zkoBiKLZDAuD
o4tHX/20FzZv34rWS/y8qwOMSJ4k1nHzaila2SVZ5xRm2ZZHwqJZxrSin0xXTJRM
uCyqbQzIVOrrxUTg/sDGCHEPx+lLYftktXbXe+zp2jngzldxMvMQajMqK4fgipXH
T6vLfrijXxzFkTPNAWTBSozbN62NCf8nnHtS2s2zRFCBLvxdWeOZ5snWCe7YqEMC
7GUNIv9fFPPK8zA352N99tuX1UrlWjwFBtbdmP3r4VmUJ1rC3SSGtElBhTUC7Sb9
izO6usBiWYTbaTWHRtMOpQ0jiTtAGUtMbFnjZBnrkLPra+la8Yo=
=owX/
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.