{"id":"GHSA-3wxx-jxwc-mg39","summary":"bottlerocket dependency openssl has a double free vulnerability","details":"A double-free vulnerability exists in OpenSSL where it is possible to construct a malicious PEM file that has 0 bytes of payload data. This then points to data that has already been freed in memory which, when freed again, leads to a crash. Agents or clients compiled with OpenSSL may crash unexpectedly when parsing these PEM files. OpenSSL has been removed in bottlerocket/update-operator version 1.1.0 in favor of Rust-based TLS using rustls.","modified":"2023-02-09T19:31:59Z","published":"2023-02-09T19:31:59Z","database_specific":{"nvd_published_at":null,"severity":"MODERATE","cwe_ids":[],"github_reviewed_at":"2023-02-09T19:31:59Z","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator/security/advisories/GHSA-3wxx-jxwc-mg39"},{"type":"PACKAGE","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator"},{"type":"WEB","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator/releases/tag/v1.1.0"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0010.html"},{"type":"WEB","url":"https://www.openssl.org/news/secadv/20230207.txt"}],"affected":[{"package":{"name":"bottlerocket/update-operator","ecosystem":"crates.io","purl":"pkg:cargo/bottlerocket/update-operator"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-3wxx-jxwc-mg39/GHSA-3wxx-jxwc-mg39.json"}}],"schema_version":"1.7.3"}