Echo: openssl: security update to 3.5.4-1~deb13u2

high Tenable Cloud Security Plugin ID 461330

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an
ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer
dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling
TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or
NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and
ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When
the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union,
causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp
Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not
widely used and the impact of the exploit is just a Denial of Service. For these reasons the issue was
assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the
TimeStamp Response implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3,
3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue. (CVE-2025-69420)

Solution

Update the openssl library and its related packages to version 3.5.4-1~deb13u2 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-69420

Plugin Details

Severity: High

ID: 461330

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.95

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-69420

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/28/2026

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2025-69420

IAVA: 2026-A-0087-S