First published: Tue Jan 11 2022(Updated: )
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.<br>Security Fix(es):<br><li> openssl: Read buffer overruns processing ASN.1 strings (CVE-2021-3712)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openssl | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-debuginfo | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-debuginfo | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-devel | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-devel | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-libs | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-libs | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-perl | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-static | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-static | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-perl | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-debuginfo | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-devel | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-libs | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-perl | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
redhat/openssl-static | <1.0.2k-23.el7_9 | 1.0.2k-23.el7_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:0064 is classified as moderate.
To fix RHSA-2022:0064, update the OpenSSL packages to version 1.0.2k-23.el7_9.
RHSA-2022:0064 addresses a read buffer overrun vulnerability in OpenSSL identified as CVE-2021-3712.
Affected packages include openssl, openssl-devel, openssl-libs, and others in versions prior to 1.0.2k-23.el7_9.
Yes, the specific fix version for RHSA-2022:0064 is 1.0.2k-23.el7_9.