OpenSSL: CVE-2022-3602 X.509 certificate verification buffer overrun
🔗 CVE IDs covered (1)
📋 Description
Why is this OpenSSL Software Foundation CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by the Microsoft products listed in the Security Updates table and are known to be affected. It is being documented in the Security Update Guide to announce that the latest builds of these products are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
Where can I find further guidance for this OpenSSL vulnerability? For more information and guidance see Awareness and guidance related to OpenSSL 3.0 - 3.0.6 risk (CVE-2022-3786 and CVE-2202-3602).
🎯 Affected products3
- Azure SDK for C++
- Microsoft Azure Kubernetes Service
- vcpkg
✅ Remediation
KBRelease Notes (Security Update) — fixed build 2022.11.02 KBRelease Notes (Security Update)