Update OpenSSL 1.1.1j, wolfSSL 4.7.0, and LibreSSL 3.2.4

A corrective release of the OpenSSL 1.1.1j cryptographic library is available, which addresses two vulnerabilities:

  • CVE-2021-23841 — dereferencing a null pointer in the X509_issuer_and_serial_hash() function, which may lead to application crashes when this function is called to process X509 certificates with an invalid issuer field value.
  • CVE-2021-23840 — integer overflow in the EVP_CipherUpdate, EVP_EncryptUpdate, and EVP_DecryptUpdate functions, which can result in a return value of 1, indicating success, while also setting a negative size, potentially causing application crashes or unexpected behavior.
  • CVE-2021-23839 — a flaw in the implementation of rollbacks to SSLv2 protocol. This issue only occurs in the old 1.0.2 branch.

A release of LibreSSL 3.2.4 has also been published; this project, developed as a fork of OpenSSL by OpenBSD, aims to provide a higher level of security. This release is notable for reverting to the old certificate verification code used in LibreSSL 3.1.x, due to some applications malfunctioning with workarounds for bugs in the old code. Highlights include the addition of exporter and autochain components in TLSv1.3.

Additionally, a new release of the compact cryptographic library wolfSSL 4.7.0 has been made, optimized for use on embedded devices with limited CPU and memory resources, such as Internet of Things devices, smart home systems, automotive infotainment systems, routers, and mobile phones. The code is written in C and is distributed under the GPLv2 license.

The new version implements support for RFC 5705 (Keying Material Exporters for TLS) and S/MIME (Secure/Multipurpose Internet Mail Extensions). A flag "--enable-reproducible-build" has been added to ensure reproducible builds. The API SSL_get_verify_mode, X509_VERIFY_PARAM API, and X509_STORE_CTX have been added for compatibility with OpenSSL. A macro WOLFSSL_PSK_IDENTITY_ALERT has been implemented. A new function _CTX_NoTicketTLSv12 has been added to disable session tickets in TLS 1.2 while retaining them for TLS 1.3.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster