INFSA-2024:7848: OpenSSL security update

Information about definition

Identificator: INFSA-2024:7848

Type: security

Release date: 2024-10-23 10:35:23 UTC

Information about package

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Vulnerabilities description

  • CVE-2024-5535

    A flaw was found in OpenSSL. Affected versions of this package are vulnerable to Information Exposure through the SSL_select_next_proto function. This flaw allows an attacker to cause unexpected application behavior or a crash by exploiting the buffer overread condition when the function is called with a zero-length client list. This issue is only exploitable if the application is misconfigured to use a zero-length server list and mishandles the 'no overlap' response in ALPN or uses the output as the opportunistic protocol in NPN.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-5535
no information 5.9 no information
Critical, important, moderate, low

Updated packages