Cryptographic issues in OpenSSL - CVE-2023-5363
Published: October 24, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error when processing key and initialisation vector lengths in EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() and EVP_CipherInit_ex2() function. A remote attacker can gain access to potentially sensitive information.
The following ciphers and cipher modes are impacted: RC2, RC4, RC5, CCM, GCM and OCB.
Affected software
IBM AIX
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Linux Enterprise Micro
IBM i
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Basesystem Module
openSUSE Leap
Junos OS Evolved
Ubuntu
Anolis OS
openEuler
IBM VIOS
Red Hat OpenShift Builds
Service Interconnect
Splunk DB Connect
OpenShift Logging
Custom Metrics Autoscaler Operator for Red Hat OpenShift
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Migration Toolkit for Applications
IBM MQ for HPE NonStop
IBM Rational ClearCase
IBM QRadar WinCollect Agent
IBM Observability with Instana
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
HP-UX OpenSSL
Storage Resource Manager
Storage Ceph
Storage Protect for Virtual Environments: Data Protection for VMware
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Container Platform
Nessus Network Monitor
VMware Horizon Client
LANTIME Operating System Firmware (LTOS)
FOS Firmware
OptiPlex Small Form Factor 7010
Precision 3460 Small Form Factor
Precision 3460 XE Small Form Factor
Precision 3450
Precision 3420 Tower
Precision 3280 CFF
Precision 3260 Compact
Precision 3260 XE Compact
OptiPlex XE4 Tower
OptiPlex XE4 SFF
OptiPlex Tower 7020
OptiPlex Tower Plus 7010
OptiPlex Tower 7010
OptiPlex Small Form Factor Plus 7010
Precision 3581
OptiPlex SFF 7020
OptiPlex Micro 7020
OptiPlex Micro Plus 7010
OptiPlex Micro 7010
Alienware x17 R1
OptiPlex AIO 7420
OptiPlex 7780 All-in-One
OptiPlex 7770 All-In-One
OptiPlex 7760 All-In-One
OptiPlex 7490 All-in-One
OptiPlex 7480 All-in-One
OptiPlex 7470 All-In-One
Vostro 5880
Alienware Area 51m R2
Alienware m15 R3
Alienware m15 R4
Alienware m17 R3
Alienware m17 R4
Alienware x14
Alienware x14 R2
Alienware x15 R1
Alienware x15 R2
Alienware x16 R1
XPS 13 Plus 9320
XPS 13 9315
Vostro 5890
Precision 3580
Vostro 5090
Vostro 3890
Vostro 15 3530
Vostro 15 3520
Vostro 14 3430
Vostro 14 3420
Precision 3930 Rack
Precision 3680 Tower
Precision 3660
Precision 3650 Tower
Precision 3640
Precision 3620 Tower
OptiPlex All-in-One 7410
Latitude 3540
Latitude 7330 Rugged Laptop
Latitude 7230 Rugged Extreme
Latitude 7220 Rugged Extreme
Latitude 7030 Rugged Extreme
Latitude 5540
Latitude 5430 Rugged Laptop
Latitude 5424 Rugged
Latitude 5420 Rugged
OptiPlex 7460 All In One
Latitude 5310 2-IN-1
Latitude 5310
Latitude 5300 2-IN-1
Latitude 5300
Latitude 5340
Latitude 3440
Latitude 3340
Latitude 3310 2-in-1
Latitude 3310
Inspiron 3891
Inspiron 15 3530
Inspiron 15 3520
Precision 7920 Tower
Precision 7820 Tower
Precision 5820 Tower
Precision 3630 Tower
Dell G5 5090
Alienware x17 R2
Latitude 7424 Rugged Extreme
OptiPlex 7450 All-In-One
OptiPlex 7400 All-In-One
Optiplex 7090 Ultra
OptiPlex 7090 Tower
OptiPlex 7000
OptiPlex 5490 All-In-One
OptiPlex 5480 All-In-One
OptiPlex 5400 All-In-One
OptiPlex 5270 All-In-One
OptiPlex 5260 All-In-One
OptiPlex 5090
OptiPlex 5080
Latitude 7340
OptiPlex 5000
OptiPlex 3280 All-in-One
OptiPlex 3090 Ultra
Latitude 9440 2-in-1
Latitude Rugged 7220EX
OptiPlex 3000
OptiPlex 3000 Thin Client
OptiPlex 3050 All-In-One
OptiPlex 3080
OptiPlex 3090
Latitude 3390 2-in-1
OptiPlex 3050
OptiPlex 5050
Latitude 3300
MySQL Server
MySQL Enterprise Monitor
IBM InfoSphere Information Server
MySQL Connectors
MySQL Workbench
IBM App Connect Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssl3 (Ubuntu package)
openssl (Red Hat package)
openssl
libopenssl3-debuginfo
libopenssl3-64bit-debuginfo
libopenssl3-64bit
libopenssl-3-devel-64bit
openssl-3-doc
libopenssl-3-devel-32bit
libopenssl3-32bit
libopenssl3-32bit-debuginfo
openssl-3-debuginfo
libopenssl3
openssl-3-debugsource
libopenssl-3-devel
openssl-3
openssl (Debian package)
openssl-devel
openssl-libs
openssl-perl
openssl-doc
edk2
python3-edk2-devel
edk2-ovmf
edk2-help
edk2-aarch64
edk2-devel
edk2-debugsource
edk2-debuginfo
Cisco Jabber
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Cisco Webex Meetings
IBM MaaS360 VPN Module
Dell EMC Storage Monitoring and Reporting (SMR)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Precision 3240 Compact
OptiPlex 7071
How to mitigate CVE-2023-5363
Red Hat OpenShift Builds - update to 1.0.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Interconnect - update to 1.5.3
Splunk DB Connect - update to 4.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.14.17, 4.15.0, 4.15.3
OpenShift Logging - update to 5.8.6
Nessus Network Monitor - update to 6.3.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
MySQL Server - update to 8.3.0
MySQL Enterprise Monitor - update to 8.0.37
MySQL Connectors - update to 8.3.0
MySQL Workbench - update to 8.0.36
FOS Firmware - update to 9.2.2
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.10.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
HP-UX OpenSSL - update to A.03.00.15.001
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.12, 3.0.8-1ubuntu1.4, 3.0.10-1ubuntu2.1
openssl (Red Hat package) - update to 3.0.7-18.el9_2
openssl - update to 3.0.8-1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl3 - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
openssl-3 - addressed in versions 3.0.8-150400.4.37.1, 3.0.8-150500.5.14.1
openssl (Debian package) - update to 3.0.11-1~deb12u2
openssl - update to 3.0.12-1
openssl-devel - update to 3.0.12-1
openssl-libs - update to 3.0.12-1
openssl-perl - update to 3.0.12-1
openssl-doc - update to 3.0.12-1
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 VPN Module - update to 3.000.400
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
Red Hat Migration Toolkit for Applications - update to 6.2
Storage Ceph - update to 7.0z1
IBM MQ for HPE NonStop - update to 8.1.0.17
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.23.0
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
IBM QRadar WinCollect Agent - update to 10.1.9
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Observability with Instana - update to 272
OptiPlex Small Form Factor 7010 - update to 2413.5.68.0
Precision 3460 Small Form Factor - update to 2413.5.68.0
Precision 3460 XE Small Form Factor - update to 2413.5.68.0
Precision 3450 - update to 2413.5.68.0
Precision 3420 Tower - update to 2413.5.68.0
Precision 3280 CFF - update to 2413.5.68.0
Precision 3260 Compact - update to 2413.5.68.0
Precision 3260 XE Compact - update to 2413.5.68.0
Precision 3240 Compact - update to 2413.5.68.0
OptiPlex XE4 Tower - update to 2413.5.68.0
OptiPlex XE4 SFF - update to 2413.5.68.0
OptiPlex Tower 7020 - update to 2413.5.68.0
OptiPlex Tower Plus 7010 - update to 2413.5.68.0
OptiPlex Tower 7010 - update to 2413.5.68.0
OptiPlex Small Form Factor Plus 7010 - update to 2413.5.68.0
Precision 3581 - update to 2413.5.68.0
OptiPlex SFF 7020 - update to 2413.5.68.0
OptiPlex Micro 7020 - update to 2413.5.68.0
OptiPlex Micro Plus 7010 - update to 2413.5.68.0
OptiPlex Micro 7010 - update to 2413.5.68.0
Alienware x17 R1 - update to 2413.5.68.0
OptiPlex AIO 7420 - update to 2413.5.68.0
OptiPlex 7780 All-in-One - update to 2413.5.68.0
OptiPlex 7770 All-In-One - update to 2413.5.68.0
OptiPlex 7760 All-In-One - update to 2413.5.68.0
OptiPlex 7490 All-in-One - update to 2413.5.68.0
OptiPlex 7480 All-in-One - update to 2413.5.68.0
OptiPlex 7470 All-In-One - update to 2413.5.68.0
Vostro 5880 - update to 2413.5.68.0
Alienware Area 51m R2 - update to 2413.5.68.0
Alienware m15 R3 - update to 2413.5.68.0
Alienware m15 R4 - update to 2413.5.68.0
Alienware m17 R3 - update to 2413.5.68.0
Alienware m17 R4 - update to 2413.5.68.0
Alienware x14 - update to 2413.5.68.0
Alienware x14 R2 - update to 2413.5.68.0
Alienware x15 R1 - update to 2413.5.68.0
Alienware x15 R2 - update to 2413.5.68.0
Alienware x16 R1 - update to 2413.5.68.0
XPS 13 Plus 9320 - update to 2413.5.68.0
XPS 13 9315 - update to 2413.5.68.0
Vostro 5890 - update to 2413.5.68.0
Precision 3580 - update to 2413.5.68.0
Vostro 5090 - update to 2413.5.68.0
Vostro 3890 - update to 2413.5.68.0
Vostro 15 3530 - update to 2413.5.68.0
Vostro 15 3520 - update to 2413.5.68.0
Vostro 14 3430 - update to 2413.5.68.0
Vostro 14 3420 - update to 2413.5.68.0
Precision 3930 Rack - update to 2413.5.68.0
Precision 3680 Tower - update to 2413.5.68.0
Precision 3660 - update to 2413.5.68.0
Precision 3650 Tower - update to 2413.5.68.0
Precision 3640 - update to 2413.5.68.0
Precision 3620 Tower - update to 2413.5.68.0
OptiPlex All-in-One 7410 - update to 2413.5.68.0
Latitude 3540 - update to 2413.5.68.0
Latitude 7330 Rugged Laptop - update to 2413.5.68.0
Latitude 7230 Rugged Extreme - update to 2413.5.68.0
Latitude 7220 Rugged Extreme - update to 2413.5.68.0
Latitude 7030 Rugged Extreme - update to 2413.5.68.0
Latitude 5540 - update to 2413.5.68.0
Latitude 5430 Rugged Laptop - update to 2413.5.68.0
Latitude 5424 Rugged - update to 2413.5.68.0
Latitude 5420 Rugged - update to 2413.5.68.0
OptiPlex 7460 All In One - update to 2413.5.68.0
Latitude 5310 2-IN-1 - update to 2413.5.68.0
Latitude 5310 - update to 2413.5.68.0
Latitude 5300 2-IN-1 - update to 2413.5.68.0
Latitude 5300 - update to 2413.5.68.0
Latitude 5340 - update to 2413.5.68.0
Latitude 3440 - update to 2413.5.68.0
Latitude 3340 - update to 2413.5.68.0
Latitude 3310 2-in-1 - update to 2413.5.68.0
Latitude 3310 - update to 2413.5.68.0
Inspiron 3891 - update to 2413.5.68.0
Inspiron 15 3530 - update to 2413.5.68.0
Inspiron 15 3520 - update to 2413.5.68.0
Precision 7920 Tower - update to 2413.5.68.0
Precision 7820 Tower - update to 2413.5.68.0
Precision 5820 Tower - update to 2413.5.68.0
Precision 3630 Tower - update to 2413.5.68.0
Dell G5 5090 - update to 2413.5.68.0
Alienware x17 R2 - update to 2413.5.68.0
Latitude 7424 Rugged Extreme - update to 2413.5.68.0
OptiPlex 7450 All-In-One - update to 2413.5.68.0
OptiPlex 7400 All-In-One - update to 2413.5.68.0
Optiplex 7090 Ultra - update to 2413.5.68.0
OptiPlex 7090 Tower - update to 2413.5.68.0
OptiPlex 7071 - update to 2413.5.68.0
OptiPlex 7000 - update to 2413.5.68.0
OptiPlex 5490 All-In-One - update to 2413.5.68.0
OptiPlex 5480 All-In-One - update to 2413.5.68.0
OptiPlex 5400 All-In-One - update to 2413.5.68.0
OptiPlex 5270 All-In-One - update to 2413.5.68.0
OptiPlex 5260 All-In-One - update to 2413.5.68.0
OptiPlex 5090 - update to 2413.5.68.0
OptiPlex 5080 - update to 2413.5.68.0
Latitude 7340 - update to 2413.5.68.0
OptiPlex 5000 - update to 2413.5.68.0
OptiPlex 3280 All-in-One - update to 2413.5.68.0
OptiPlex 3090 Ultra - update to 2413.5.68.0
Latitude 9440 2-in-1 - update to 2413.5.68.0
Latitude Rugged 7220EX - update to 2413.5.68.0
OptiPlex 3000 - update to 2413.5.68.0
OptiPlex 3000 Thin Client - update to 2413.5.68.0
OptiPlex 3050 All-In-One - update to 2413.5.68.0
OptiPlex 3080 - update to 2413.5.68.0
OptiPlex 3090 - update to 2413.5.68.0
Latitude 3390 2-in-1 - update to 2435.6.35.0
OptiPlex 3050 - update to 2435.6.35.0
OptiPlex 5050 - update to 2435.6.35.0
Latitude 3300 - update to 2435.6.35.0
edk2 - addressed in versions 202308-17, 202308-18
python3-edk2-devel - addressed in versions 202308-17, 202308-18
edk2-ovmf - addressed in versions 202308-17, 202308-18
edk2-help - addressed in versions 202308-17, 202308-18
edk2-aarch64 - addressed in versions 202308-17, 202308-18
edk2-devel - addressed in versions 202308-17, 202308-18
edk2-debugsource - addressed in versions 202308-17, 202308-18
edk2-debuginfo - addressed in versions 202308-17, 202308-18
External References
Related Security Bulletins
- Information disclosure in OpenSSL
- Ubuntu update for openssl
- Debian update for openssl
- SUSE update for openssl-3
- SUSE update for openssl-3
- Tenable Nessus Network Monitor update for third-party components
- IBM MQ for HPE NonStop update for OpenSSL
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Cryptographic issues in MySQL Connectors
- Cryptographic issues in IBM App Connect Enterprise
- Red Hat Enterprise Linux 9.2 Extended Update Support update for openssl
- Multiple vulnerabilities in IBM AIX and IBM VIOS
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift for RHEL 9
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Service Interconnect 1.5
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Junos OS Evolved update for OpenSSL
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments: Data Protection for VMware
- Cryptographic issues in Storage Ceph
- Dell Client Platform update for OpenSSL
- Multiple vulnerabilities in HP-UX Using OpenSSL
- Amazon Linux AMI update for openssl
- openEuler 24.03 LTS SP1 update for edk2
- openEuler 24.03 LTS update for edk2
- IBM FOS firmware update for OpenSSL
- Anolis OS update for openssl
- Splunk DB Connect update for third-party components
- Meinberg LANTIME firmware update for third-party components (January 2024)
- Splunk DB Connect update for third-party components
- Multiple vulnerabilities in IBM i