Skip to content

openssl CVE-2023-0215

Moderate
bcressey published GHSA-qhqf-v7jj-v4w7 Mar 13, 2023

Package

openssl (bottlerocket-test-system)

Affected versions

< 0.0.6

Patched versions

0.0.6

Description

An OpenSSL public API provides streaming of ASN.1 data via a BIO. It is possible for a malicious third party to use the BIO to access unfreed memory pointers that are not cleaned up after execution of the API. Freeing these memory pointers will result in a crash. Agents and clients compiled with OpenSSL may see unexpected crashes.

Severity

Moderate

CVE ID

CVE-2023-0215

Weaknesses

No CWEs