HomeSecurityOpenSSL releases patch for high severity flaw

OpenSSL releases patch for high-severity flaw

The OpenSSL project maintainers have released patches to address a high-severity bug in the cryptographic library that could potentially lead to remote code execution under certain scenarios.

See also: Apple: New Lockdown Mode will offer protection against spyware

OpenSSL

The issue, now assigned the identifier CVE-2022-2274, has been described as a heap memory corruption issue with RSA private key functionality introduced in OpenSSL version 3.0.4 released on June 21, 2022.

See also: SHI International: Hit by malware attack

OpenSSL, first released in 1998, is a general-purpose cryptography library that provides an open-source implementation of the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, allowing users to generate private keys, create certificate signing requests (CSRs), and install SSL/TLS certificates.

"SSL/TLS servers or other servers using 2048-bit RSA private keys running on machines that support AVX512IFMA instructions on the X86_64 architecture are affected by this issue," the announcement notes.

Calling it a “serious bug in the RSA implementation,” the maintainers said the flaw could lead to memory corruption during computation that could be weaponized by an attacker to enable remote code execution on the machine performing the computation.

OpenSSL releases patch for high-severity flaw

See also: Marriott: New data breach for the hotel chain

Xi Ruoyao, a Ph.D. student at Xidian University, reported the flaw in OpenSSL on June 22, 2022. Users of the library are advised to upgrade to OpenSSL version 3.0.5 to mitigate any potential threats.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS