QID 240798

Date Published: 2022-11-02

QID 240798: Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2022:7288)

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full strength general purpose cryptography library.

Security Fix(es):
OpenSSL: X.509 Email Address Buffer Overflow (CVE-2022-3602)
OpenSSL: X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

Red Hat Product Security has rated this update as having a security impact of Important.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to Red Hat security advisory RHSA-2022:7288 for updates and patch information.
    Vendor References

    CVEs related to QID 240798

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2022:7288 URL Logo access.redhat.com/errata/RHSA-2022:7288