CVE-2024-5535 OpenSSL 1.0.2

Hi Team,

We are using confd 6.2.1 which uses libcrypto.so.1.0.2k for its startup. And it is detected as vulnerability and suggesting to go with 1.0.2zk which has fix. Please suggest how to go about this?

Hi, there are several good references to how to use a different version of OpenSSL on this site (e.g. Using a different version of OpenSSL ) and the User Guide has a section that has instructions as well.
Regards,

Scott

Hi @sbarvick ,

Can you please let me know which version of open ssl needs to use for confd 6.2.1 libcrypto.so for startup link

Hi, that is further back than we go. We know that 7.1 can run with 1.0.0t but you probably should try to go later and see if you can run with 1.1.1 to be as recent as possible.

I hope that helps,

Scott