Skip to content

OpenSSL 2023.09 updates.#175

Merged
dumol merged 39 commits intomasterfrom
openssl-2023-sep-updates
Oct 13, 2023
Merged

OpenSSL 2023.09 updates.#175
dumol merged 39 commits intomasterfrom
openssl-2023-sep-updates

Conversation

@dumol
Copy link
Copy Markdown
Contributor

@dumol dumol commented Sep 21, 2023

Scope

Patch latest OpenSSL known vulnerabilities, as published at https://www.openssl.org/news/vulnerabilities.html#y2023.

Changes

Updated OpenSSL 1.1.1t sources to version 1.1.1w to fix CVE-2023-4807, CVE-2023-3817, CVE-2023-3446, CVE-2023-2975, CVE-2023-2975, CVE-2023-2975, CVE-2023-1255, CVE-2023-0466, CVE-2023-0464.

Drive-by changes:

How to try and test the changes

reviewers: @adiroiban

Check automated tests.

Check relevant changes:

git diff master .github/ brink.* chevah_build python-modules/ src/python/

Check the updated external_deps.fods LibreOffice sheet for documented security issues.

Check the updated list of ignored safety security alerts, e.g. https://data.safetycli.com/vulnerabilities/CVE-2023-38325/59473/ (cryptography issue not related to embedded OpenSSL and with no backported fix).

@dumol dumol self-assigned this Sep 21, 2023
@dumol
Copy link
Copy Markdown
Contributor Author

dumol commented Oct 6, 2023

Testing packages are tried in https://github.com/chevah/server/pull/6400.

@dumol
Copy link
Copy Markdown
Contributor Author

dumol commented Oct 13, 2023

The 2.7.18.b45ecf2 testing packages are already used in SFTPPlus 4.33.0.

To avoid their automatic removal, they've been copied manually to production at https://bin.chevah.com:20443/production/2.7.18.b45ecf2/ without being released through GitHub releases.

@dumol dumol merged commit c063ec2 into master Oct 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants