Copied from
ubuntu mantic in
Private PPA for Ubuntu Security Team
by Marc Deslauriers
Changelog
openssl (3.0.10-1ubuntu2.1) mantic-security; urgency=medium
* SECURITY UPDATE: Incorrect cipher key and IV length processing
- debian/patches/CVE-2023-5363-1.patch: process key length and iv
length early if present in crypto/evp/evp_enc.c.
- debian/patches/CVE-2023-5363-2.patch: add unit test in
test/evp_extra_test.c.
- CVE-2023-5363
-- Marc Deslauriers <email address hidden> Fri, 13 Oct 2023 07:51:05 -0400