QID 376202
QID 376202: Reuse
Cygwin is a Linux-style operating environment for Microsoft Windows.
Affected Versions:
Cygwin openssl package prior to OpenSSL 1.1.1l
Cygwin openssl package prior to OpenSSL 1.0.2u.
QID Detection Logic (authenticated):
The QID flags if it finds a vulnerable version of the git package in installed file. The location of the file is determined by the key "HKLM\SOFTWARE\Cygwin\setup", value "rootdir". The file is present in the <rootdir>\etc\setup folder.
It could result in the disclosure of private memory contents also might crash causing Denial of Service attack
Solution
Upgrade to Cygwin openssl package to version OpenSSL 1.0.2u or OpenSSL 1.1.1l. Download Packages Cygwin packages
Vendor References
- Cygwin OpenSSL -
cygwin.com/pipermail/cygwin-announce/2021-November/010327.html - Cygwin Openssl -
cygwin.com/pipermail/cygwin-announce/2021-November/010326.html
CVEs related to QID 376202
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 010326 |
|
||
| 010327 |
|