from Hacker News

Forthcoming OpenSSL Releases – Critical Issue in OpenSSL 3

by TimWolla on 10/25/22, 2:17 PM with 6 comments

  • by yuvadam on 10/25/22, 6:41 PM

    This seems to affect only OpenSSL 3.x.x

    Most distros have never bothered to upgrade to major version 3 - possibly because it broke ABI backwards compatibility - so despite the critical severity the impact might not be as widespread as it could have been?

  • by SLWW on 10/25/22, 4:39 PM

    RCE and unprivileged access to memory? (to dump keys and the like)

    seems fun

  • by midislack on 10/25/22, 9:15 PM

    No cute name / logo for this one?