Re: OpenSSL 3.3.3 Security Vulnerability

Tomas Mraz <[email protected]> Wed, 08 Oct 2025 18:25:03 +0200
Newsgroups gmane.comp.encryption.openssl.user,gmane.comp.encryption.openssl.devel
Message-ID <[email protected]>
Your tool is most likely misdetecting the version.

Tomas Mraz, OpenSSL Foundation

On Wed, 2025-10-08 at 13:00 +0000, Prasad, PCRaghavendra wrote:
>=20
>=20
>=20
> Any input on this will be appreciated.
> For our current release we need to decide based on this.
> =C2=A0
> Thanks in advance
> =C2=A0
>=20
> Internal Use - Confidential
>=20
>=20
> From: Prasad, PCRaghavendra
> Sent: Wednesday, October 1, 2025 8:29 AM
> To: [email protected]; [email protected]
> Subject: OpenSSL 3.3.3 Security Vulnerability
> =C2=A0
> =C2=A0
> Hi Team,
> =C2=A0
> We are currently on OpenSSL 3.3.3 version. On this version there is
> security vulnerability.
> To fix this we have upgraded the version to OpenSSL 3.3.4 which is
> mentioned that will resolve the issue.
> But in OpenSSL 3.3.4, our blackduck tool is showing two versions one
> is 3.3.3 and another is 3.3.4
> libssl - 3.3.3
> libcrypto - 3.3.4
> =C2=A0
> So untill now in OpenSSL we didnt see 2 different versions being
> carried? why is this version having multiple versions of openssl?
> can we take this version for the resolution of=C2=A0CVE-2025-27587?
> =C2=A0
> Thanks,
> Raghavendra
> =C2=A0

--=20
Tom=C3=A1=C5=A1 Mr=C3=A1z, Public Support and Security Manager, OpenSSL Fou=
ndation
Join the Code Protectors or support us on Github Sponsors
https://openssl-foundation.org/donate/

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/1c17a75fa0e6564306c10d131b26212b5d901c3a.camel%40openssl.o=
rg.