Skip to content

openssl CVE-2023-0401

High
bcressey published GHSA-pfc9-74gj-5gw3 Mar 13, 2023

Package

openssl (bottlerocket-test-system)

Affected versions

< 0.0.6

Patched versions

0.0.6

Description

A null pointer in OpenSSL can be dereferenced when signatures are being verified in malformed PKCS7 data. Agents or clients compiled with OpenSSL may experience unexpected crashes.

Severity

High

CVE ID

CVE-2023-0401

Weaknesses

No CWEs