Lucene search

K
cloudlinuxCloudLinuxCLSA-2023:1683236532
HistoryMay 04, 2023 - 9:42 p.m.

openssl: Fix of 3 CVEs

2023-05-0421:42:17
repo.cloudlinux.com
90
openssl
x.509
cve-2023-0464
resource use
cve-2023-0466
documentation
cve-2022-3996
flag setting
policy_cache_set_mapping
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

72.6%

  • CVE-2023-0464: Fix excessive resource use verifying X.509 policy constraints
  • CVE-2023-0466: Fix documentation of X509_VERIFY_PARAM_add0_policy()
  • CVE-2022-3996: Drop redundant flag setting in policy_cache_set_mapping()

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.004

Percentile

72.6%