We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected.
Reserved 2025-04-15 | Published 2025-05-13 | Updated 2025-05-22 | Assigner cisa-cgCWE-427 Uncontrolled Search Path Element
github.com/...ommit/066e83c5226bafe90a9c0575b077ce30cd5f5921 (url)
github.com/conda-forge/openssl-feedstock/issues/201 (url)
Support options