VYPR

apk package

chainguard/openssl-provider-fips

pkg:apk/chainguard/openssl-provider-fips

Vulnerabilities (43)

  • CVE-2022-4304MedFeb 8, 2023
    affected < 3.0.8-r0fixed 3.0.8-r0

    A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of

  • CVE-2022-3996HigDec 13, 2022
    affected < 3.0.8-r0fixed 3.0.8-r0

    If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy proce

  • CVE-2022-3602HigNov 1, 2022
    affected < 3.0.8-r0fixed 3.0.8-r0

    A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue

Page 3 of 3