OpenSSL vulnerabilities ‘not as bad as feared’

General News

Summary

Memories of Heartbleed led many to suspect an issue of similar import, but in the event, the disclosure passed off without causing widespread panic, and the initial critical status of the vulnerability was downgraded to high. CVE-2022-3786 differs slightly in that an attacker can only exploit it by crafting a malicious email address to overflow an arbitrary number of bytes that contain the period character. “Vendors and operators should update their dependencies on OpenSSL to 3.0.7 when it’s practical to do so, respecting normal change control procedures and taking into account the specific risk profile for those organisations. Ilgayev explained that ultimately, the biggest takeaway from this incident for security pros is the need to keep comprehensive and maintained software bill of materials (SBOMs). “We should treat this exercise seriously to poke holes and find weaknesses in our SBOMs and PBOMs as recent history – Heartbleed, Struts, Jackson-databind, LodDash Log4Shell, Log4Text, and so on – demonstrates there’s always another major dependency just over the horizon,” said Ilgayev.

Classifications

industries
EduTech - institutions
applications
Web and Content Management

AskAI Classifications

Labels
Cybersecurity Software SaaS SIEM Software

Linked Companies

Mobilisafe
up to $1M
Rapid7
$500M to $1B