Skip to content

openssl CVE-2023-0217

Moderate
cbgbt published GHSA-g3mh-7255-vpg6 Feb 9, 2023

Package

openssl (bottlerocket-update-operator)

Affected versions

< 1.1.0

Patched versions

1.1.0

Description

An invalid pointer dereference can occur in OpenSSL during read of a malformed DSA public key. Agents and clients compiled with OpenSSL may see crashes when attempting to read malformed or malicious DSA data.

Severity

Moderate

CVE ID

CVE-2023-0217

Weaknesses

No CWEs