Re: OpenSSL 3.3.3 Security Vulnerability
Tomas Mraz <[email protected]> Wed, 08 Oct 2025 18:25:03 +0200
| Newsgroups | gmane.comp.encryption.openssl.user,gmane.comp.encryption.openssl.devel |
|---|---|
| Message-ID | <[email protected]> |
Your tool is most likely misdetecting the version. Tomas Mraz, OpenSSL Foundation On Wed, 2025-10-08 at 13:00 +0000, Prasad, PCRaghavendra wrote: >=20 >=20 >=20 > Any input on this will be appreciated. > For our current release we need to decide based on this. > =C2=A0 > Thanks in advance > =C2=A0 >=20 > Internal Use - Confidential >=20 >=20 > From: Prasad, PCRaghavendra > Sent: Wednesday, October 1, 2025 8:29 AM > To: [email protected]; [email protected] > Subject: OpenSSL 3.3.3 Security Vulnerability > =C2=A0 > =C2=A0 > Hi Team, > =C2=A0 > We are currently on OpenSSL 3.3.3 version. On this version there is > security vulnerability. > To fix this we have upgraded the version to OpenSSL 3.3.4 which is > mentioned that will resolve the issue. > But in OpenSSL 3.3.4, our blackduck tool is showing two versions one > is 3.3.3 and another is 3.3.4 > libssl - 3.3.3 > libcrypto - 3.3.4 > =C2=A0 > So untill now in OpenSSL we didnt see 2 different versions being > carried? why is this version having multiple versions of openssl? > can we take this version for the resolution of=C2=A0CVE-2025-27587? > =C2=A0 > Thanks, > Raghavendra > =C2=A0 --=20 Tom=C3=A1=C5=A1 Mr=C3=A1z, Public Support and Security Manager, OpenSSL Fou= ndation Join the Code Protectors or support us on Github Sponsors https://openssl-foundation.org/donate/ --=20 You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/1c17a75fa0e6564306c10d131b26212b5d901c3a.camel%40openssl.o= rg.