Updated CHANGES and NEWS for CVE-2024-6119 fix

Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
This commit is contained in:
Viktor Dukhovni 2024-07-10 19:50:57 +10:00 committed by Tomas Mraz
parent 7dfcee2cd2
commit cf384d35aa
2 changed files with 17 additions and 2 deletions

View File

@ -28,7 +28,17 @@ OpenSSL 3.3
### Changes between 3.3.1 and 3.3.2 [xx XXX xxxx] ### Changes between 3.3.1 and 3.3.2 [xx XXX xxxx]
* none yet * Fixed possible denial of service in X.509 name checks.
Applications performing certificate name checks (e.g., TLS clients checking
server certificates) may attempt to read an invalid memory address when
comparing the expected name with an `otherName` subject alternative name of
an X.509 certificate. This may result in an exception that terminates the
application program.
[(CVE-2024-6119)]
*Viktor Dukhovni*
### Changes between 3.3.0 and 3.3.1 [4 Jun 2024] ### Changes between 3.3.0 and 3.3.1 [4 Jun 2024]
@ -20665,6 +20675,7 @@ ndif
<!-- Links --> <!-- Links -->
[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119
[CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741 [CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741
[CVE-2024-4603]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4603 [CVE-2024-4603]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4603
[CVE-2024-2511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-2511 [CVE-2024-2511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-2511

View File

@ -23,7 +23,10 @@ OpenSSL 3.3
### Major changes between OpenSSL 3.3.1 and OpenSSL 3.3.2 [under development] ### Major changes between OpenSSL 3.3.1 and OpenSSL 3.3.2 [under development]
* none OpenSSL 3.3.2 is a security patch release. The most severe CVE fixed in this
release is Moderate.
* Fixed possible denial of service in X.509 name checks [(CVE-2024-6119)].
### Major changes between OpenSSL 3.3.0 and OpenSSL 3.3.1 [4 Jun 2024] ### Major changes between OpenSSL 3.3.0 and OpenSSL 3.3.1 [4 Jun 2024]
@ -1733,6 +1736,7 @@ OpenSSL 0.9.x
<!-- Links --> <!-- Links -->
[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119
[CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741 [CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741
[CVE-2024-4603]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4603 [CVE-2024-4603]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4603
[CVE-2024-2511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-2511 [CVE-2024-2511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-2511