Skip to content

openssl CVE-2023-0215

Moderate
cbgbt published GHSA-j79x-vvgm-w73w Feb 9, 2023

Package

openssl (bottlerocket-update-operator)

Affected versions

< 1.1.0

Patched versions

1.1.0

Description

An OpenSSL public API provides streaming of ASN.1 data via a BIO. It is possible for a malicious third party to use the BIO to access unfreed memory pointers that are not cleaned up after execution of the API. Freeing these memory pointers will result in a crash. Agents and clients compiled with OpenSSL may see unexpected crashes.

Severity

Moderate

CVE ID

CVE-2023-0215

Weaknesses

No CWEs