Threat Advisory

OpenSSL Releases Patch for 2 New High-Severity Vulnerabilities

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

The OpenSSL has issued a patch for two high-severity vulnerabilities related to email address buffer overflows that could lead to denial-of-service crashes or potentially remote code execution. The two vulnerabilities include the X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786), which can be exploited by attackers via malicious email addresses to trigger a denial-of-service state via a buffer overflow and,  X.509 Email Address 4-Byte Buffer Overflow (CVE-2022-3602), it is an arbitrary 4-byte stack buffer overflow that could trigger crashes or lead to remote code execution.[/subscribe_to_unlock_form]

Summary:

The OpenSSL has issued a patch for two high-severity vulnerabilities related to email address buffer overflows that could lead to denial-of-service crashes or potentially remote code execution. The two vulnerabilities include the X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786), which can be exploited by attackers via malicious email addresses to trigger a denial-of-service state via a buffer overflow and,  X.509 Email Address 4-Byte Buffer Overflow (CVE-2022-3602), it is an arbitrary 4-byte stack buffer overflow that could trigger crashes or lead to remote code execution.[emaillocker id="1283"]

Recommendation:

We strongly recommend you to patch the said vulnerabilities and update to the latest version of 3.0.7.

References:

The following reports contain further technical details:

https://www.openssl.org/news/vulnerabilities.html

[/emaillocker]
crossmenu