Summary:
The OpenSSL has issued a patch for two high-severity vulnerabilities related to email address buffer overflows that could lead to denial-of-service crashes or potentially remote code execution. The two vulnerabilities include the X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786), which can be exploited by attackers via malicious email addresses to trigger a denial-of-service state via a buffer overflow and, X.509 Email Address 4-Byte Buffer Overflow (CVE-2022-3602), it is an arbitrary 4-byte stack buffer overflow that could trigger crashes or lead to remote code execution.[/subscribe_to_unlock_form]
Summary:
The OpenSSL has issued a patch for two high-severity vulnerabilities related to email address buffer overflows that could lead to denial-of-service crashes or potentially remote code execution. The two vulnerabilities include the X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786), which can be exploited by attackers via malicious email addresses to trigger a denial-of-service state via a buffer overflow and, X.509 Email Address 4-Byte Buffer Overflow (CVE-2022-3602), it is an arbitrary 4-byte stack buffer overflow that could trigger crashes or lead to remote code execution.[emaillocker id="1283"]
Recommendation:
We strongly recommend you to patch the said vulnerabilities and update to the latest version of 3.0.7.
References:
The following reports contain further technical details:
[/emaillocker]