• openssl_1.1.1f-1ubuntu2.8 ()
  • 1.1.1f-1ubuntu2.23
  • 2024-09-23 14:30:12
  • CVE CVE-2024-4741, CVSSv2 Score: 5.6
  • Description:

    A use-after-free vulnerability was found in OpenSSL. Calling the OpenSSL API SSL_free_buffers function may cause memory to be accessed that was previously freed in some situations.

  • CVE CVE-2024-5535, CVSSv2 Score: 5.9
  • Description:

    A flaw was found in OpenSSL. Affected versions of this package are vulnerable to Information Exposure through the SSL_select_next_proto function. This flaw allows an attacker to cause unexpected application behavior or a crash by exploiting the buffer overread condition when the function is called with a zero-length client list.