#OpenSSL 1.1.1s and 3.0.7 are out today to patch two high-security vulnerabilities (CVE-2022-3786 and CVE-2022-3602). Update your systems as soon as possible! More details at https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/

#Linux #OpenSource #infosec #infosecurity

CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows - OpenSSL Blog

Today we published an advisory about CVE-2022-3786 (“X.509 Email Address Variable Length Buffer Overflow”) and CVE-2022-3602 (“X.509 Email Address 4- …

FYI: 1.1.1s is just a bugfix release as version 1.1 LTS is not affected by those security flaws!
OpenSSL 3.0.7 already landed in #ArchLinux, Alpine Linux, #Debian, and #Ubuntu. More distros will release updates soon so make sure that you patch your systems on a regular basis!