Skip to content

openssl CVE-2022-4203

Moderate
bcressey published GHSA-c2r8-8x5x-2pcr Mar 13, 2023

Package

openssl (bottlerocket-test-system)

Affected versions

< 0.0.6

Patched versions

0.0.6

Description

A read buffer overflow can be triggered in OpenSSL X.509 verification during name constraint checking. Note that this occurs after the certificate chain has been verified and would require a compromised CA. This can cause a client or agent compiled with OpenSSL to crash unexpectedly.

Severity

Moderate

CVE ID

CVE-2022-4203

Weaknesses

No CWEs