Re: OpenSSL 3.3.3 Security Vulnerability

Marian Beermann <[email protected]> Tue, 21 Oct 2025 22:45:34 +0200
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
 > OpenSSL 3.0.0 through 3.3.2 *on the PowerPC architecture* is 
vulnerable to a Minerva attack,

Are you actually shipping powerpc binaries?

 > This CVE is disputed because the OpenSSL security policy explicitly 
notes that any side channels which require same physical system to be 
detected are outside of the threat model for the software. The timing 
signal is so small that it is infeasible to be detected without having 
the attacking process running on the same physical system.

Is this actually your threat model?

 > So untill now in OpenSSL we didnt see 2 different versions being 
carried? why is this version having multiple versions of openssl?

You should discuss blackduck misdetections with your vendor (Black Duck 
Software Inc.), since they are unrelated to the OpenSSL project.

Cheers, Marian

On 10/1/25 04:58, 'Prasad, PCRaghavendra' via openssl-users wrote:
>
> Hi Team,
>
> We are currently on OpenSSL 3.3.3 version. On this version there is 
> security vulnerability.
> To fix this we have upgraded the version to OpenSSL 3.3.4 which is 
> mentioned that will resolve the issue.
>
> But in OpenSSL 3.3.4, our blackduck tool is showing two versions one 
> is 3.3.3 and another is 3.3.4
>
> libssl - 3.3.3
> libcrypto - 3.3.4
>
> So untill now in OpenSSL we didnt see 2 different versions being 
> carried? why is this version having multiple versions of openssl?
> can we take this version for the resolution of CVE-2025-27587 
> <https://github.com/advisories/GHSA-jqr3-3jm7-r6cm>?
>
> Thanks,
>
> Raghavendra
>
>
> Internal Use - Confidential
>
> -- 
> You received this message because you are subscribed to the Google 
> Groups "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it, send 
> an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
> To view this discussion visit 
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/MN2PR19MB4029FD1265BD0B502C95E167EBE6A%40MN2PR19MB4029.namprd19.prod.outlook.com 
> <https://groups.google.com/a/openssl.org/d/msgid/openssl-users/MN2PR19MB4029FD1265BD0B502C95E167EBE6A%40MN2PR19MB4029.namprd19.prod.outlook.com?utm_medium=email&utm_source=footer>.

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aa46cb1f-3f03-4ccc-97e4-1cb7f79cedaa%40enkore.de.