Alpine: libcrypto3, multiple openssl packages: security update to 3.5.1-r0

medium Tenable Self-Hosted Container Security Plugin ID 428282

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a
rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected
for a particular use it will be instead marked as trusted for that use. A copy & paste error during minor
refactoring of the code introduced this issue in the OpenSSL 3.5 version. If, for example, a trusted CA
certificate should be trusted only for the purpose of authenticating TLS servers but not for CMS signature
verification and the CMS signature verification is intended to be marked as rejected with the -addreject
option, the resulting CA certificate will be trusted for CMS signature verification purpose instead. Only
users which use the trusted certificate format who use the openssl x509 command line application to add
rejected uses are affected by this issue. The issues affecting only the command line application are
considered to be Low severity. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by
this issue. OpenSSL 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1 and 1.0.2 are also not affected by this issue.
(CVE-2025-4575)

See Also

https://security.alpinelinux.org/vuln/CVE-2025-4575

Plugin Details

Severity: Medium

ID: 428282

Version: Revision 1.9

Type: Local

Published: 7/3/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 6.91

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2025-4575

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/22/2025

Reference Information

CVE: CVE-2025-4575

IAVA: 2025-A-0378