CVE-2022-3358 - OpenSSL

Support for security such as Firewalls and securing linux
Post Reply
rwk
Posts: 3
Joined: 2022/11/02 21:35:28

CVE-2022-3358 - OpenSSL

Post by rwk » 2022/11/03 14:27:07

Hello,

I'm looking for confirmation that the CentOS 7 openssl package does not contain the vulnerable code as described in Red Hat's CVE response to CVE-2022-3358.

https://access.redhat.com/security/cve/cve-2022-3358

Thank you

User avatar
TrevorH
Site Admin
Posts: 33216
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2022-3358 - OpenSSL

Post by TrevorH » 2022/11/03 15:40:15

From the linked bugzilla entry off the CVE page...

"Fixed in OpenSSL 3.0.6 (Affected 3.0.0-3.0.5)"

CentOS 7 uses openssl 1.0.2k.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Post Reply