apk package
chainguard/openssl-provider-fips
pkg:apk/chainguard/openssl-provider-fips
Vulnerabilities (43)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-4304 | Med | 5.9 | < 3.0.8-r0 | 3.0.8-r0 | Feb 8, 2023 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of | |
| CVE-2022-3996 | Hig | 7.5 | < 3.0.8-r0 | 3.0.8-r0 | Dec 13, 2022 | If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy proce | |
| CVE-2022-3602 | Hig | 7.5 | < 3.0.8-r0 | 3.0.8-r0 | Nov 1, 2022 | A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue |
- affected < 3.0.8-r0fixed 3.0.8-r0
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of
- affected < 3.0.8-r0fixed 3.0.8-r0
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy proce
- affected < 3.0.8-r0fixed 3.0.8-r0
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue
Page 3 of 3