QID 105980
Date Published: 2021-06-10
QID 105980: EOL/Obsolete Software: Open Secure Sockets Layer (OpenSSL) 0.9.8 through 1.1.0 Detected
OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols OpenSSL Versions 1.1.0, 1.0.1, 1.0.0 and 0.9.8 are no longer supported. No further releases or security fixes will be available Users of these older versions are encouraged to upgrade to 1.1.1 as soon as possible.
Affected Versions and EOL:
OpenSSL Version 0.9.8 : 31st December 2015
OpenSSL Version 1.0.0 : 31st December 2015
OpenSSL Version 1.0.1 : 31st December 2016
The system is at high risk of being exposed to security vulnerabilities. Since the vendor no longer provides updates, obsolete software is more vulnerable to viruses and other attacks.
Solution
Customers are advised to upgrade to the latest supported version of OpenSSL. Refer to OpenSSL Downloads for more details.
Vendor References
- OpenSSL End of Life Policy -
www.openssl.org/policies/releasestrat.html
CVEs related to QID 105980
Software Advisories
| Advisory ID | Software | Component | Link |
|---|