Skip to content

openssl CVE-2023-0216

Moderate
bcressey published GHSA-4f8h-j6m7-8w36 Mar 13, 2023

Package

openssl (bottlerocket-test-system)

Affected versions

< 0.0.6

Patched versions

0.0.6

Description

If an application using OpenSSL attempts to load malformed PKCS7 data, an invalid pointer dereference on read can be triggered. Agents and clients compiled with OpenSSL may see crashes when attempting to read malformed or malicious data.

Severity

Moderate

CVE ID

CVE-2023-0216

Weaknesses

No CWEs