CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.9 are vulnerable due to insecure file permissions in the desktop GUI, which allows decrypted plaintext files to be created with world-readable defaults. This flaw enables unprivileged local users on multi-user systems to access sensitive decrypted output files, potentially leading to data exposure. Organizations using affected versions of OpenSSL, particularly those operating in multi-user environments, should prioritize patching to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems.