Skip to content

openssl CVE-2023-0216

Moderate
cbgbt published GHSA-5cqv-q2r8-xpx2 Feb 9, 2023

Package

openssl (bottlerocket-update-operator)

Affected versions

< 1.1.0

Patched versions

1.1.0

Description

If an application using OpenSSL attempts to load malformed PKCS7 data, an invalid pointer dereferncee on read can be triggered. Agents and clients compiled with OpenSSL may see crashes when attempting to read malformed or malicious data.

Severity

Moderate

CVE ID

CVE-2023-0216

Weaknesses

No CWEs