# OpenSSL Patches X.509 Buffer Overflow Flaw

Published: 2022-11-01 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/66c4d938-9437-5dd0-80ac-eda35b0da0a7/openssl-patches-x-509-buffer-overflow-flaw

> A buffer overflow in OpenSSL's X.509 certificate verification can let attackers trigger DoS or remote code execution via malicious certificates.

IPA issued an advisory regarding a buffer overflow vulnerability in OpenSSL, an open-source library providing SSL/TLS functionality. The flaw occurs during X.509 certificate verification processing, where a specially crafted malicious certificate could trigger a buffer overflow, potentially leading to denial-of-service conditions or remote code execution.

OpenSSL versions 1.1.1 and 1.0.2 are not affected by this issue. The developers have released updated versions that address the vulnerability, and IPA urges affected organizations to update to the latest versions promptly given the potential for expanded exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2022-3602

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20221102.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/66c4d938-9437-5dd0-80ac-eda35b0da0a7/openssl-patches-x-509-buffer-overflow-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
