Collected every two hours from specialised publications — each link leads to the original article.
update openssl (CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4304). ---- cherry-pick aarch64 bugfixes, set firmware build release date, add ext4 sub-p…
**MySQL 8.0.30** Changes: Native OpenSSL 3 support Log-rotate file fixed - it now has correct log location, but has to be enabled manually https://dev.mysql.co…
**MySQL 8.0.30** Changes: Native OpenSSL 3 support Log-rotate file fixed - it now has correct log location, but has to be enabled manually https://dev.mysql.co…
Update to 5.62 including new features and bugfixes: Security bugfixes - The "redirect" option was fixed to properly handle unauthenticated requests (bsc#118252…
Heap out-of-bound read vulnerability in rr_frm_str_internal function Heap out-of-bound read vulnerability in ldns_nsec3_salt_data function Fixed time memory co…
**MariaDB 10.5.13** Release notes: https://mariadb.com/kb/en/mariadb-10513-release-notes/ Maintainer notes: This update contains - conditionally only on=35 - p…
**MariaDB 10.5.13** Release notes: https://mariadb.com/kb/en/mariadb-10513-release-notes/ Maintainer notes: This update contains - conditionally only on=35 - p…
Cybersecurity researchers have disclosed aÂnovel technique adopted by a threat actor to deliberately evade detection with the help of malformed digital signatu…
Apache Tomcat did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet…
Offensive Security has released Kali Linux 2021.3 with a new set of tools, improved virtualization support, and a new OpenSSL configuration that increases the …
When constructing an OpenSSL EC public or private key from PKCS#11 attributes or ECDH public data, check that the key is valid, i.e. that the point is on the c…
Debian 10.10 has been released with the latest security updates. Some popular packages that have received updates in this update include the Linux Kernel, Nvid…
QSslSocket incorrectly calls SSL_shutdown() in OpenSSL mid-handshake causing denial of service in TLS applications (CVE-2020-13962) This update provides additi…
- Use Apple upstream instead of non-fresh Github one - New upstream in 1.8 dev branch with 417.1 subversion - Close CVE-2018-17093 - Close CVE-2018-17094 - Clo…
- Use Apple upstream instead of non-fresh Github one - New upstream in 1.8 dev branch with 417.1 subversion - Close CVE-2018-17093 - Close CVE-2018-17094 - Clo…
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509…
**Added:** * amqp_ssl_socket_get_context can be used to get the current OpenSSL CTX* associated with a connection. **Changed:** * openssl: missing OpenSSL c…
**Added:** * amqp_ssl_socket_get_context can be used to get the current OpenSSL CTX* associated with a connection. **Changed:** * openssl: missing OpenSSL c…
A change introduced in openssl 1.1.1d (which got released as DSA 4539-1) requires sandboxing features which are not available in Linux kernels before 3.19, res…