• [SECURITY] [DSA 4475-1] openssl security update

    From Moritz Muehlenhoff@1:229/2 to All on Mon Jul 1 23:20:01 2019
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4475-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    July 01, 2019 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : openssl
    CVE ID : CVE-2019-1543

    Joran Dirk Greef discovered that overly long nonces used with
    ChaCha20-Poly1305 were incorrectly processed and could result in nonce
    reuse. This doesn't affect OpenSSL-internal uses of ChaCha20-Poly1305
    such as TLS.

    For the stable distribution (stretch), this problem has been fixed in
    version 1.1.0k-1~deb9u1. This DSA also upgrades openssl1.0 (which
    itself is not affected by CVE-2019-1543) to 1.0.2s-1~deb9u1

    We recommend that you upgrade your openssl packages.

    For the detailed security status of openssl please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/openssl

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl0adR4ACgkQEMKTtsN8 Tjbh4RAArq1enTQE05VZeU6jPVXsMcZXUbFlGrMysFqUvGiR9UZaOwbFYhtmXKH9 4sjCGFRJXpyHkY2P33r6G+NmGEimD24ZdcLZnnZzO5y3uPpNsGvmBZwROt63E3zM jXCigJAFSoJV5wctIZmD0HsaIJng1VlYXEkLI9UKA+xLYaklSFB8hSQsxeDbgazv TqFjFJa6e7l2B81LRBC4bs0X5VmXrZKOrKcteGvSRVdtQsPnimjaEmtWVjVdzYAm zGbEBOVckTiaYVrk9qTXHX4o4NUGuZlssLPTMK636ypMriN/Idd8g5wQFgEzYUGm 0efOFIvOIQh/ziOndA3GeWNrb7LM9Nb8viGtkRw6LoNvcjsSFNeiH36MPhc2wcqZ HuO6UgIHmbmNFWucTCrmHdIitYJI9IJRDPOtG4lCO9AXbrZR+jRup2Q4+XYx937H cF18bjgfIKUJ9FcKX3X/knsgfhxkFzFORycarE7lLWafr/8SxnxbZGGDyK00hTym bQIpp/H9kOIR0dFXlahwkHMQl4b8SA1kUqf6Ts+3KceaCSQ7GilGJ6eZob1/CyQo 1xmRJvi28fwbyeuQDxtmXm/HcjkPnucYN47lwWNIE/sjmdTnstbImz4ehUuMRrkf PQjhjhBgorRGcZbcqGyMfnZAr/Y9m+6pzXjdprSu8ZsfP1ATrKw=
    =tnxv
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)