Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2022.0255
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2022-0255)
Summary:The remote host is missing an update for the 'openssl' package(s) announced via the MGASA-2022-0255 advisory.
Description:Summary:
The remote host is missing an update for the 'openssl' package(s) announced via the MGASA-2022-0255 advisory.

Vulnerability Insight:
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised
implementation will not encrypt the entirety of the data under some
circumstances. This could reveal sixteen bytes of data that was
preexisting in the memory that wasn't written. In the special case of 'in
place' encryption, sixteen bytes of the plaintext would be revealed. Since
OpenSSL does not support OCB based cipher suites for TLS and DTLS, they
are both unaffected. (CVE-2022-2097)

Affected Software/OS:
'openssl' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-2097
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93
https://www.openssl.org/news/secadv/20220705.txt
Debian Security Information: DSA-5343 (Google Search)
https://www.debian.org/security/2023/dsa-5343
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK/
https://security.gentoo.org/glsa/202210-02
https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.