Over-Hyped OpenSSL Vulnerability November 2022

Опубликовано: 15 Октябрь 2024
на канале: quidsup
4,069
157

There was an announcement that OpenSSL 3.0.7 was due to be released on 1st November 2022 and that it would contain a security-fix rated at Critical.
This was subsequently over-hyped by the Infosec community, and the vulnerability was downgraded to High prior to the patch release.

Users of OpenSSL 3.0.0 to 3.0.6 should apply updates at your convenience.
The vulnerability does not affect older releases of OpenSSL.

Vulnerabilities Patched:
X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602)
X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

Sources:
https://mta.openssl.org/pipermail/ope...
https://www.cisa.gov/uscert/ncas/aler...
https://www.globalsign.com/en/blog/ur...
https://techcommunity.microsoft.com/t...
https://isc.sans.edu/forums/diary/Upc...
https://www.openssl.org/news/secadv/2...
https://www.openssl.org/blog/blog/202...

Like my channel? Please help support it:
Paypal: https://www.paypal.me/quidsup

Follow me on Social Media
Twitter:   / quidsup  
MeWe: https://mewe.com/i/quidsup
Minds: https://minds.com/quidsup

#OpenSSL
#CyberSecurity
#OverHyped
#QuidsupLinux