<p>The openSSL component, versions 3.0.0 through 3.0.6, contains two
buffer overflow vulnerabilities (CVE-2022-3602, CVE-2022-3786) in the
X.509 certificate verification [0]. They could allow an attacker to
create a denial of service condition or execute arbitrary code on a
vulnerable TLS server (if the server requests client certificate
authentication), or on a vulnerable TLS client.</p>
<p>Siemens has released updates for several affected products and
recommends to update to the latest versions. Siemens is preparing
further updates and recommends specific countermeasures for products
where updates are not, or not yet available.</p>
<p>[0] <a href="https://www.openssl.org/news/secadv/20221101.txt"
class="uri">https://www.openssl.org/news/secadv/20221101.txt</a></p>
Source link
Subscribe to Updates
Get the latest creative news from FooBar about art, design and business.
Previous ArticlePSIRT | FortiGuard Labs
Related Posts
Add A Comment