Skip to content

OpenSSL CVE-2022-4304 Timing Oracle in RSA Decryption #22374

Answered by tom-cosgrove-arm
iyyapa asked this question in Q&A
Discussion options

You must be logged in to vote

OpenSSL 1.0.2 went out of support in 2019, as far as I can tell.

OpenSSL 1.0.2zg is available for premium support customers, so if you are a premium support customer please reach out to your support contact.

Looking at the OpenSSL vulnerability list, rather than the Rust version, since 1.1.1 is also end-of-life now, if you're not a premium support customer, you should upgrade to 3.0.8

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
3 replies
@iyyapa
Comment options

@rsbeckerca
Comment options

@iyyapa
Comment options

Answer selected by t8m
Comment options

You must be logged in to vote
1 reply
@iyyapa
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants