<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Guidance for OpenSSL Vulnerability Disclosures (02/07/23) in Expedition Articles</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-articles/guidance-for-openssl-vulnerability-disclosures-02-07-23/ta-p/530918</link>
    <description>&lt;DIV class="lia-message-template-symptoms-zone"&gt;
&lt;H2&gt;Advisory:&lt;/H2&gt;
&lt;P&gt;Guidance for OpenSSL Vulnerability Disclosures (02/07/23)&lt;/P&gt;
&lt;P&gt;CVE-2022-4304&lt;BR /&gt;CVE-2022-4450&lt;BR /&gt;CVE-2023-0215&lt;BR /&gt;CVE-2023-0286&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Affected version&lt;/STRONG&gt;: Impacts all versions of OpenSSL 1.1.1 (installed default version on Ubuntu 20 is 1.1.1f-1ubuntu2.16)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-diagnosis-zone"&gt;
&lt;H2&gt;Diagnosis&lt;/H2&gt;
&lt;P&gt;Execute below two commands to check the version of openssl and libssl1.1:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;apt list --installed | grep openssl/focal-updates&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;STRONG&gt;apt list --installed | grep libssl1.1&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="error"&gt;if the output showing version less than&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;1.1.1f-1ubuntu2.17 amd64&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;, you will need to perform the steps to upgrade the openssl and libssl1.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-solution-zone"&gt;
&lt;H2&gt;Solution&lt;/H2&gt;
&lt;P&gt;In Expedition CLI execute below commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Update the package index:&lt;BR /&gt;&lt;STRONG&gt;sudo apt-get update&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Install deb lib packages:&lt;BR /&gt;&lt;STRONG&gt;sudo apt-get install openssl&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;sudo apt-get install libssl1.1&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Check packages are installed&lt;BR /&gt;&lt;STRONG&gt;apt list --installed | grep openssl/focal-updates&lt;/STRONG&gt;&lt;BR /&gt;Expected output: openssl/focal-updates,focal-security,now 1.1.1f-1ubuntu2.17 amd64&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="error"&gt;[installed]&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;apt list --installed | grep libssl1.1&lt;/STRONG&gt;&lt;BR /&gt;Expected output: libssl1.1/focal-updates,focal-security,now 1.1.1f-1ubuntu2.17 amd64&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="error"&gt;[installed,automatic]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 13 Feb 2023 18:47:19 GMT</pubDate>
    <dc:creator>lychiang</dc:creator>
    <dc:date>2023-02-13T18:47:19Z</dc:date>
    <item>
      <title>Guidance for OpenSSL Vulnerability Disclosures (02/07/23)</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-articles/guidance-for-openssl-vulnerability-disclosures-02-07-23/ta-p/530918</link>
      <description>&lt;DIV class="lia-message-template-symptoms-zone"&gt;
&lt;H2&gt;Advisory:&lt;/H2&gt;
&lt;P&gt;Guidance for OpenSSL Vulnerability Disclosures (02/07/23)&lt;/P&gt;
&lt;P&gt;CVE-2022-4304&lt;BR /&gt;CVE-2022-4450&lt;BR /&gt;CVE-2023-0215&lt;BR /&gt;CVE-2023-0286&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Affected version&lt;/STRONG&gt;: Impacts all versions of OpenSSL 1.1.1 (installed default version on Ubuntu 20 is 1.1.1f-1ubuntu2.16)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-diagnosis-zone"&gt;
&lt;H2&gt;Diagnosis&lt;/H2&gt;
&lt;P&gt;Execute below two commands to check the version of openssl and libssl1.1:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;apt list --installed | grep openssl/focal-updates&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;STRONG&gt;apt list --installed | grep libssl1.1&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="error"&gt;if the output showing version less than&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;1.1.1f-1ubuntu2.17 amd64&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;, you will need to perform the steps to upgrade the openssl and libssl1.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-solution-zone"&gt;
&lt;H2&gt;Solution&lt;/H2&gt;
&lt;P&gt;In Expedition CLI execute below commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Update the package index:&lt;BR /&gt;&lt;STRONG&gt;sudo apt-get update&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Install deb lib packages:&lt;BR /&gt;&lt;STRONG&gt;sudo apt-get install openssl&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;sudo apt-get install libssl1.1&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Check packages are installed&lt;BR /&gt;&lt;STRONG&gt;apt list --installed | grep openssl/focal-updates&lt;/STRONG&gt;&lt;BR /&gt;Expected output: openssl/focal-updates,focal-security,now 1.1.1f-1ubuntu2.17 amd64&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="error"&gt;[installed]&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;apt list --installed | grep libssl1.1&lt;/STRONG&gt;&lt;BR /&gt;Expected output: libssl1.1/focal-updates,focal-security,now 1.1.1f-1ubuntu2.17 amd64&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="error"&gt;[installed,automatic]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Feb 2023 18:47:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-articles/guidance-for-openssl-vulnerability-disclosures-02-07-23/ta-p/530918</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-02-13T18:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Guidance for OpenSSL Vulnerability Disclosures (02/07/23)</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-articles/guidance-for-openssl-vulnerability-disclosures-02-07-23/tac-p/531373#M384</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A id="link_8" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38629" target="_self" aria-label="View Profile of lychiang"&gt;&lt;SPAN class=""&gt;Lychiang&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May I know if this is the remediation/workaround for the abovementioned CVEs?&lt;/P&gt;
&lt;P&gt;I checked Palo Alto advisories as well but there is no mention of this as this is still an ongoing investigation.&lt;/P&gt;
&lt;P&gt;Also, what about these CVEs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- CVE-2022-4203&lt;BR /&gt;- CVE-2023-0216&lt;BR /&gt;- CVE-2023-0217&lt;BR /&gt;- CVE-2023-0401&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 09:58:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-articles/guidance-for-openssl-vulnerability-disclosures-02-07-23/tac-p/531373#M384</guid>
      <dc:creator>Johnson_Tan</dc:creator>
      <dc:date>2023-02-16T09:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Guidance for OpenSSL Vulnerability Disclosures (02/07/23)</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-articles/guidance-for-openssl-vulnerability-disclosures-02-07-23/tac-p/531447#M385</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223422"&gt;@Johnson_Tan&lt;/a&gt;&amp;nbsp;Yes this article is to address the mentioned CVE:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;CVE-2022-4304&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2022-4450&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2023-0215&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CVE-2023-0286&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the CVEs you mentioned, there is no fix from openssl yet.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 17:12:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-articles/guidance-for-openssl-vulnerability-disclosures-02-07-23/tac-p/531447#M385</guid>
      <dc:creator>lychiang</dc:creator>
      <dc:date>2023-02-16T17:12:21Z</dc:date>
    </item>
  </channel>
</rss>

