|
|
Re: OpenSSL fixes two high severity vulnerabilities [message #153105 is a reply to message #153082] |
Sun, 13 November 2022 05:35   |
Nick.Geary
Messages: 73 Registered: January 2021
|
|
|
|
I've looked into the matter and these vulnerabilities impact all versions of OpenSSL between 3.0.0 - 3.0.6.
From what I've found, Kerio Control is running the ongoing development OpenSSL 1.1.1 branch which would not be impacted by the vulnerability.
Kerio Control release notes, lists the most recent mention of OpenSSL was upgrading with the release of Kerio Control 9.3.6.1 where "The OpenSSL library is upgraded from 1.0.2j to 1.1.1d."
For Kerio Connect, the most recent Engineering ticket was tracking the upgrade of OpenSSL to version OpenSSL 1.1.1o which is also not impacted.
In any case, I will engage with our Engineering Team for further confirmation.
Nick Geary
GFI Software
[Updated on: Thu, 17 November 2022 16:14] Report message to a moderator
|
|
|
|