OpenSSL Releases Security Updates
High impact security updates address potential RCE and a denial-of-service condition
Summary
High impact security updates address potential RCE and a denial-of-service condition
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
OpenSSL has released a security update to address two high severity vulnerabilities known as CVE-2022-3786 and CVE-2022-3602. These vulnerabilities are caused by a X.509 email address 4-byte buffer overflow or a variable length buffer overflow. A malicious attacker could exploit these vulnerabilities to perform a denial-of-service (DoS) attack on an affected system or potentially allow remote code execution (RCE) in certain configurations.
Remediation advice
Affected organisations are encouraged to review the OpenSSL security advisory and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 2 November 2022 12:17 pm