{"id":"GHSA-pj34-fpw3-83qj","summary":"bottlerocket dependency openssl is vulnerable to read buffer overflow via X.509 verification","details":"A read buffer overflow can be triggered in OpenSSL X.509 verification during name constraint checking. Note that this occurs after the certificate chain has been verified and would require a compromised CA. This can cause a client or agent compiled with OpenSSL to crash unexpectedly. OpenSSL has been removed in bottlerocket/update-operator version 1.1.0 in favor of Rust-based TLS using rustls.","modified":"2023-02-09T19:31:25Z","published":"2023-02-09T19:31:25Z","database_specific":{"cwe_ids":[],"github_reviewed_at":"2023-02-09T19:31:25Z","github_reviewed":true,"nvd_published_at":null,"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator/security/advisories/GHSA-pj34-fpw3-83qj"},{"type":"PACKAGE","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator"},{"type":"WEB","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator/releases/tag/v1.1.0"},{"type":"WEB","url":"https://www.openssl.org/news/secadv/20230207.txt"}],"affected":[{"package":{"name":"bottlerocket/update-operator","ecosystem":"crates.io","purl":"pkg:cargo/bottlerocket/update-operator"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-pj34-fpw3-83qj/GHSA-pj34-fpw3-83qj.json"}}],"schema_version":"1.7.3"}