QID 376202

QID 376202: Reuse

Cygwin is a Linux-style operating environment for Microsoft Windows.

Affected Versions:
Cygwin openssl package prior to OpenSSL 1.1.1l
Cygwin openssl package prior to OpenSSL 1.0.2u.

QID Detection Logic (authenticated):
The QID flags if it finds a vulnerable version of the git package in installed file. The location of the file is determined by the key "HKLM\SOFTWARE\Cygwin\setup", value "rootdir". The file is present in the <rootdir>\etc\setup folder.

It could result in the disclosure of private memory contents also might crash causing Denial of Service attack

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Upgrade to Cygwin openssl package to version OpenSSL 1.0.2u or OpenSSL 1.1.1l. Download Packages Cygwin packages

    CVEs related to QID 376202

    Software Advisories
    Advisory ID Software Component Link
    010326 URL Logo cygwin.com/pipermail/cygwin-announce/2021-November/010326.html
    010327 URL Logo cygwin.com/pipermail/cygwin-announce/2021-November/010327.html