Skip to content

openssl CVE-2022-4203

Moderate
cbgbt published GHSA-pj34-fpw3-83qj Feb 9, 2023

Package

openssl (bottlerocket-update-operator)

Affected versions

< 1.1.0

Patched versions

1.1.0

Description

A read buffer overflow can be triggered in OpenSSL X.509 verification during name constraint checking. Note that this occurs after the certificate chain has been verified and would require a compromised CA. This can cause a client or agent compiled with OpenSSL to crash unexpectedly.

Severity

Moderate

CVE ID

CVE-2022-4203

Weaknesses

No CWEs