Skip to main content

OpenSSL Releases Security Updates

High impact security updates address potential RCE and a denial-of-service condition

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

High impact security updates address potential RCE and a denial-of-service condition


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

OpenSSL has released a security update to address two high severity vulnerabilities known as CVE-2022-3786 and CVE-2022-3602. These vulnerabilities are caused by a X.509 email address 4-byte buffer overflow or a variable length buffer overflow. A malicious attacker could exploit these vulnerabilities to perform a denial-of-service (DoS) attack on an affected system or potentially allow remote code execution (RCE) in certain configurations.


Remediation advice

Affected organisations are encouraged to review the OpenSSL security advisory and apply any relevant updates.



CVE Vulnerabilities

Last edited: 2 November 2022 12:17 pm