Update:01 November 2022 12:57 PM PDT The OpenSSL Project has officially disclosed two high-severity vulnerabilities:CVE-2022-3602 and CVE-2022-3786.These CVEs impact all OpenSSL versions after 3.0.The sole exception is version 3.0.7, which contains fixes for those latest vulnerabilities.Previously, these CVEs were thought to be “critical.” ––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––– Our title and original post below (written October 27th, 2022) have been updated:

What are they?

CVE-2022-3602 is an arbitrary 4-byte stack buffer overflow that could trigger crashes

Just published by Docker: Read more