libssl1.1 wrong fix? #4196
Replies: 5 comments
-
Hello @partizanes For OS packages(
You need to update/remove this package. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
-
@DmitriyLewen |
Beta Was this translation helpful? Give feedback.
-
you have 2 package:
|
Beta Was this translation helpful? Give feedback.
-
Thank you for answer! But i already have libssl3(.0.2-0ubuntu1.9 amd64) and can`t remove libssl1.1 because have dependency in ubuntu OS 22.04 (ubuntu-minimal, python3 and etc ) apt list --installed | grep ssl
At the beginning, 1.1.1f-1ubuntu2 was installed on the system and to update it, I downloaded the openssl-1.1.1t.tar.gz sources, compiled them and selected the files needed for libssl1.1, after which I built the libssl1.1_1.1.1t_amd64 package. deb Can you please tell me how can I remove or replace the vulnerable package? |
Beta Was this translation helpful? Give feedback.
-
Hello @partizanes I checked NVD and looks like But there is some problem to exclude these CVEs from result: Ubuntu doesn't have information about This is special case, so i think you can filter these CVE or create module to handle these CVE. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
-
Hello, anyone can me explain why for libssl1.1 proposed fix as a package 3.0.2 version and how can fix that?
I have
libssl1.1/now 1.1.1t amd64 [installed,local]
libssl3/jammy-updates,jammy-security,now 3.0.2-0ubuntu1.9 amd64 [installed,automatic]
openssl/jammy-updates,jammy-security,now 3.0.2-0ubuntu1.9 amd64 [installed]
Thank you!
Beta Was this translation helpful? Give feedback.
All reactions