SUSE-SU-2022:3843-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3843-1
SUSE-SU-2022:3843-1
Summary: Security update for openssl-3
Details: This update for openssl-3 fixes the following issues: - CVE-2022-3358: Fixed vulnerability where a custom cipher passed to EVP_CipherInit() could lead into NULL encryption being unexpectedly used (bsc#1204226). - CVE-2022-3602: Fixed a buffer overflow in the X.509 email address. (bsc#1204714) - CVE-2022-3786: Fixed another buffer overflow related to X.509 email address. (bsc#1204714)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223843-1/, https://bugzilla.suse.com/1204226, https://bugzilla.suse.com/1204714, https://www.suse.com/security/cve/CVE-2022-3358, https://www.suse.com/security/cve/CVE-2022-3602, https://www.suse.com/security/cve/CVE-2022-3786
Affected packages
Package
Name: openssl-3
Purl: pkg:rpm/suse/openssl-3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
