Security alert: high-severity vulnerability affecting OpenSSL V3 and higher
ID: ca9e9215-d48c-5392-bdf9-db0cf9f6dd61
STIX ID: report--ca9e9215-d48c-5392-bdf9-db0cf9f6dd61
Feed Name: Expel Blog
OpenSSL released version 3.0.7 to address two high-severity X.509 email-address buffer overflow vulnerabilities (CVE-2022-3602 and CVE-2022-3786) affecting OpenSSL 3.0.0–3.0.6; CVE-2022-3602 can potentially enable remote code execution under constrained conditions while CVE-2022-3786 can cause denial of service. Exploitation is limited by requirements such as a certificate signed by a trusted CA or ignored verification, only four attacker-controlled bytes for one flaw, and common memory protections, but users should upgrade to 3.0.7 as soon as reasonable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
