Skip to content

openssl CVE-2022-3786

High
rpkelly published GHSA-7qch-chrr-5h74 Nov 1, 2022

Package

openssl (bottlerocket-sdk)

Affected versions

0.23.0-0.27.0

Patched versions

0.28.0

Description

A stack-based buffer overflow was found in the way OpenSSL processes X.509 certificates with a specially crafted email address field. This issue could cause a server or a client application compiled with OpenSSL to crash or possibly execute remote code when trying to process the malicious certificate.

References

CVE-2022-3786
OpenSSL blog

Severity

High

CVE ID

CVE-2022-3786

Weaknesses

No CWEs