ELA-580-1 openssl security update

denial of service

2022-03-17
Packageopenssl
Version1.0.1t-1+deb8u17
Related CVEs CVE-2022-0778


Tavis Ormandy discovered that the BN_mod_sqrt() function of OpenSSL could be tricked into an infinite loop. This could result in denial of service via malformed certificates.



For Debian 8 jessie, these problems have been fixed in version 1.0.1t-1+deb8u17.

We recommend that you upgrade your openssl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.