Skip to content

openssl CVE-2022-3602

High
bcressey published GHSA-rhgw-r286-2cph Nov 2, 2022

Package

openssl (bottlerocket-test-system)

Affected versions

< 0.0.3

Patched versions

0.0.3

Description

A stack-based buffer overflow was found in the way OpenSSL processes X.509 certificates with a specially crafted email address field. This issue could cause a server or a client application compiled with OpenSSL to crash or possibly execute remote code when trying to process the malicious certificate.

References

CVE-2022-3602
OpenSSL blog

Severity

High

CVE ID

CVE-2022-3602

Weaknesses

No CWEs