OpenSSL 3.3.3 Security Vulnerability

"'Prasad, PCRaghavendra' via openssl-users" <[email protected]> Wed, 1 Oct 2025 02:58:32 +0000
Newsgroups gmane.comp.encryption.openssl.user,gmane.comp.encryption.openssl.devel
Message-ID <MN2PR19MB4029FD1265BD0B502C95E167EBE6A@MN2PR19MB4029.namprd19.prod.outlook.com>
--_000_MN2PR19MB4029FD1265BD0B502C95E167EBE6AMN2PR19MB4029namp_
Content-Type: text/plain; charset="UTF-8"


Hi Team,

We are currently on OpenSSL 3.3.3 version. On this version there is security vulnerability.
To fix this we have upgraded the version to OpenSSL 3.3.4 which is mentioned that will resolve the issue.
But in OpenSSL 3.3.4, our blackduck tool is showing two versions one is 3.3.3 and another is 3.3.4
libssl - 3.3.3
libcrypto - 3.3.4

So untill now in OpenSSL we didnt see 2 different versions being carried? why is this version having multiple versions of openssl?
can we take this version for the resolution of CVE-2025-27587<https://github.com/advisories/GHSA-jqr3-3jm7-r6cm>?

Thanks,
Raghavendra



Internal Use - Confidential

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/MN2PR19MB4029FD1265BD0B502C95E167EBE6A%40MN2PR19MB4029.namprd19.prod.outlook.com.

--_000_MN2PR19MB4029FD1265BD0B502C95E167EBE6AMN2PR19MB4029namp_
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:DengXian;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:Aptos;}
@font-face
	{font-family:"\@DengXian";
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:12.0pt;
	font-family:"Aptos",sans-serif;
	mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#467886;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Aptos",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#467886" vlink=3D"#96607D" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Hi Team,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">We are currently on OpenSSL 3.3.3 version. On this v=
ersion there is security vulnerability.<br>
To fix this we have upgraded the version to OpenSSL 3.3.4 which is mentione=
d that will resolve the issue.<o:p></o:p></p>
<p class=3D"MsoNormal">But in OpenSSL 3.3.4, our blackduck tool is showing =
two versions one is 3.3.3 and another is 3.3.4<o:p></o:p></p>
<p class=3D"MsoNormal">libssl - 3.3.3<br>
libcrypto - 3.3.4<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">So untill now in OpenSSL we didnt see 2 different ve=
rsions being carried? why is this version having multiple versions of opens=
sl?<br>
can we take this version for the resolution of&nbsp;<a href=3D"https://gith=
ub.com/advisories/GHSA-jqr3-3jm7-r6cm" title=3D"CVE-2025-27587">CVE-2025-27=
587</a>?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Thanks,<o:p></o:p></p>
<p class=3D"MsoNormal">Raghavendra<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<br>
<p style=3D"font-family:Calibri;font-size:7pt;color:#737373;margin:5pt;font=
-style:normal;font-weight:normal;text-decoration:none;" align=3D"Left">
Internal Use - Confidential<br>
</p>
</body>
</html>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/MN2PR19MB4029FD1265BD0B502C95E167EBE6A%40MN2PR1=
9MB4029.namprd19.prod.outlook.com?utm_medium=3Demail&utm_source=3Dfooter">h=
ttps://groups.google.com/a/openssl.org/d/msgid/openssl-users/MN2PR19MB4029F=
D1265BD0B502C95E167EBE6A%40MN2PR19MB4029.namprd19.prod.outlook.com</a>.<br =
/>

--_000_MN2PR19MB4029FD1265BD0B502C95E167EBE6AMN2PR19MB4029namp_--