Your review has been sent successfully

OpenSSL Alert

3425
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

1 November, 2022

● High

2022-5348

All

Description:

OpenSSL has released a security update to address two vulnerabilities in the following versions:

  • OpenSSL
    • 3.0.0
    • 3.0.1
    • 3.0.2
    • 3.0.3
    • 3.0.4
    • 3.0.5
    • 3.0.6
Threats:

An attacker could exploit these vulnerabilities by doing the following:

  • Denial of Service (DoS)
  • Remote code execution (RCE) by crafting a malicious signed certificate
Best practice and Recommendations:

The CERT team encourages users to review OpenSSL security advisory and update the product to version 3.0.7:

Last updated at 1 November, 2022

Rate the content

rate-icon
up icon