Fix Raccoon vulnerability (CVE-2020-1968)
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| openssl (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
| Xenial |
Fix Released
|
Low
|
Unassigned | ||
Bug Description
Xenial's current OpenSSL (1.0.2g-
- https:/
- https:/
- https:/
Ubuntu's CVE tracker still lists this as NEEDED for Xenial:
- https:/
- https:/
Other supported Ubuntu releases use versions of OpenSSL that are not affected.
Indeed:
$ apt-cache policy openssl
openssl:
Installed: 1.0.2g-1ubuntu4.16
$ apt-get changelog openssl | grep CVE-2020-1968 || echo "Not patched"
Not patched
What is the status?

It is true that said vulnerability is not patched in xenial; but also it is low; and no public patches for it exist.
Please upgrade to bionic or focal? which are unaffected / fixes released?