RE: OpenSSL 3.3.3 Security Vulnerability

"'Prasad, PCRaghavendra' via openssl-users" <[email protected]> Tue, 21 Oct 2025 05:35:54 +0000
Newsgroups gmane.comp.encryption.openssl.user,gmane.comp.encryption.openssl.devel
Message-ID <MN2PR19MB4029E21F12A2616DE9569928EBF2A@MN2PR19MB4029.namprd19.prod.outlook.com>
Hi Team,

Please any help on this is very appreciated

Thanks,
Raghavendra



Internal Use - Confidential
From: Prasad, PCRaghavendra
Sent: Wednesday, October 8, 2025 6:31 PM
To: '[email protected]' <[email protected]>; '[email protected]' <[email protected]>
Cc: Tomas Mraz <[email protected]>
Subject: RE: OpenSSL 3.3.3 Security Vulnerability

Any input on this will be appreciated.
For our current release we need to decide based on this.

Thanks in advance

From: Prasad, PCRaghavendra
Sent: Wednesday, October 1, 2025 8:29 AM
To: [email protected]<mailto:[email protected]>; [email protected]<mailto:[email protected]>
Subject: OpenSSL 3.3.3 Security Vulnerability


Hi Team,

We are currently on OpenSSL 3.3.3 version. On this version there is security vulnerability.
To fix this we have upgraded the version to OpenSSL 3.3.4 which is mentioned that will resolve the issue.
But in OpenSSL 3.3.4, our blackduck tool is showing two versions one is 3.3.3 and another is 3.3.4
libssl - 3.3.3
libcrypto - 3.3.4

So untill now in OpenSSL we didnt see 2 different versions being carried? why is this version having multiple versions of openssl?
can we take this version for the resolution of CVE-2025-27587<https://github.com/advisories/GHSA-jqr3-3jm7-r6cm>?

Thanks,
Raghavendra

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/MN2PR19MB4029E21F12A2616DE9569928EBF2A%40MN2PR19MB4029.namprd19.prod.outlook.com.