CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.9 are vulnerable due to inadequate sanitization of recovery-slot metadata in the desktop GUI, which allows for the injection of control characters and line separators. This can lead to user deception during irreversible file removal operations, as attackers can manipulate warning messages displayed to users. Organizations using affected versions should prioritize updating to mitigate potential exploitation risks, particularly those with sensitive data handling processes.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot identifiers containing bidi overrides or line-separator characters to forge warning text and deceive users during file removal operations.
Related CVEs
Other vulnerabilities affecting the same vendor(s)