RE: OpenSSL 3.3.3 Security Vulnerability
"'Prasad, PCRaghavendra' via openssl-users" <[email protected]> Tue, 21 Oct 2025 05:35:54 +0000
| Newsgroups | gmane.comp.encryption.openssl.user,gmane.comp.encryption.openssl.devel |
|---|---|
| Message-ID | <MN2PR19MB4029E21F12A2616DE9569928EBF2A@MN2PR19MB4029.namprd19.prod.outlook.com> |
Hi Team, Please any help on this is very appreciated Thanks, Raghavendra Internal Use - Confidential From: Prasad, PCRaghavendra Sent: Wednesday, October 8, 2025 6:31 PM To: '[email protected]' <[email protected]>; '[email protected]' <[email protected]> Cc: Tomas Mraz <[email protected]> Subject: RE: OpenSSL 3.3.3 Security Vulnerability Any input on this will be appreciated. For our current release we need to decide based on this. Thanks in advance From: Prasad, PCRaghavendra Sent: Wednesday, October 1, 2025 8:29 AM To: [email protected]<mailto:[email protected]>; [email protected]<mailto:[email protected]> Subject: OpenSSL 3.3.3 Security Vulnerability Hi Team, We are currently on OpenSSL 3.3.3 version. On this version there is security vulnerability. To fix this we have upgraded the version to OpenSSL 3.3.4 which is mentioned that will resolve the issue. But in OpenSSL 3.3.4, our blackduck tool is showing two versions one is 3.3.3 and another is 3.3.4 libssl - 3.3.3 libcrypto - 3.3.4 So untill now in OpenSSL we didnt see 2 different versions being carried? why is this version having multiple versions of openssl? can we take this version for the resolution of CVE-2025-27587<https://github.com/advisories/GHSA-jqr3-3jm7-r6cm>? Thanks, Raghavendra -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/MN2PR19MB4029E21F12A2616DE9569928EBF2A%40MN2PR19MB4029.namprd19.prod.outlook.com.