-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 26 Sep 2025 20:59:22 +0200 Source: openssl Architecture: source Version: 3.0.17-1~deb12u3 Distribution: bookworm-security Urgency: medium Maintainer: Debian OpenSSL Team <pkg-openssl-devel@alioth-lists.debian.net> Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Changes: openssl (3.0.17-1~deb12u3) bookworm-security; urgency=medium . * CVE-2025-9230 (Out-of-bounds read & write in RFC 3211 KEK Unwrap) * CVE-2025-9232 (Out-of-bounds read in HTTP client no_proxy handling) Checksums-Sha1: 65e729ab9f8fcd5ce11947c26735b9ba74fa895c 2501 openssl_3.0.17-1~deb12u3.dsc 2e2718ff608eca5c8c56b9343816b6e2fd33fbec 15344831 openssl_3.0.17.orig.tar.gz 5ea9aa904dcc37418759e305b56f6ffaa4e91283 833 openssl_3.0.17.orig.tar.gz.asc 26f783772fa5e1a19a6d58e148e8e83d3dda59c4 55920 openssl_3.0.17-1~deb12u3.debian.tar.xz Checksums-Sha256: c154f89cb343b8ecda8a3cc09b8626171282266211b23bc9fef2c6276aab672a 2501 openssl_3.0.17-1~deb12u3.dsc dfdd77e4ea1b57ff3a6dbde6b0bdc3f31db5ac99e7fdd4eaf9e1fbb6ec2db8ce 15344831 openssl_3.0.17.orig.tar.gz 1f2f2c258e4a05affbc8a888accd4a2331a1e6867db6f0178e8bda85aecff62a 833 openssl_3.0.17.orig.tar.gz.asc 93bdec098a8c7c357b88b0b6608a66b16dcb9b02523f6764c6ee03a85a4352a2 55920 openssl_3.0.17-1~deb12u3.debian.tar.xz Files: d3aff0ca53c3e424c095d874354a083d 2501 utils optional openssl_3.0.17-1~deb12u3.dsc 29da5f1858afbce0077ba54f20aa9b7d 15344831 utils optional openssl_3.0.17.orig.tar.gz afdc7fd9d56de353ce8f6c5a96a89144 833 utils optional openssl_3.0.17.orig.tar.gz.asc 7e08eb810f7375e8839b2f88bf02120e 55920 utils optional openssl_3.0.17-1~deb12u3.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmjW8MEACgkQBWQfF1cS +lueXgwArWAZAch1DPxBgoEofwivYfcoZUjBIL7Jf8GDdVB/GRnmiLJyWfiurbAD uy/Q/M4k1yPxJieMkJ/L3BtZ7IdeRcGkIDZGoLAeMK8blLmTjLEsQZOTEg2z42/q nsUzCmkLe/ykIIyCENoVOMDzamum9GysC9tFi7UuKLLyPUuM790q9ZZKK+JQ7g77 2QHoxv5S+u1Bmjcbx0g09EuSzqzTlNmNRrNw6eA9iJJzzyB2Y6XePiOz0SG2jpjZ m5TP1h0yzoXsKIYUr7wWBwLpi/3lQeEZ8hF2Hmh3iOK86+31z0Efk3dzaYUApjx0 vWhClFvaz1B95PHdkrvSVdBtQZNzqfWFhQvr9QL9dX3mmQfswwA72vwBc/T3iGQ0 ZVXxWdp4lPvjbEq9RS55AhsUkPg3xp6P2iwsnPHoIiwbDDJ98J8ROdCA4gljfZ2O LZndvm1Wk32ghVN57R5MyVCjCs4Jv66SPDlJbW34LIKUP7GULkiBhSWpi2IAnr9R qz6G8UyJ =XD57 -----END PGP SIGNATURE-----