OpenSSL Releases Security Update
OpenSSL has released a security update to address eight vulnerabilities including one High Severity denial-of-service vulnerability
Summary
OpenSSL has released a security update to address eight vulnerabilities including one High Severity denial-of-service vulnerability
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
OpenSSL has issued a security update to address eight vulnerabilities including one High and seven Medium. The high severity vulnerability, referred to as CVE-2023-0286 is a type confusion in X.400 address processing within X.509 GeneralName. This could allow an attacker to pass arbitrary pointers to a memcmp call. An attacker could exploit these vulnerabilities to perform a denial-of-service (DoS) attack on an affected system.
Remediation advice
Affected organisations are encouraged to review the OpenSSL security advisory and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 9 February 2023 3:37 pm