Nessus OpenSSL 1.0.2 < 1.0.2zg Multiple Vulnerabilities
Posted: Wed Aug 09, 2023 10:33 am
RHEL 8.8 server
From another part of the scan report:
I think it is referring to /usr/local/ncpa/libssl.so.10 which comes from the NCPA RPM (v2.4.1-1el8)Nessus Plugin: 171080
OpenSSL 1.0.2 < 1.0.2zg Multiple Vulnerabilities
Plugin Output:
Reported version : 1.0.2k
Fixed version : 1.0.2zg
From another part of the scan report:
Any ideas how to verify that /usr/local/ncpa/libssl.so.10 is the offending file and what version it contains ?We are unable to retrieve version info from the following list of OpenSSL files. However, they may include their OpenSSL version in full or part at the end of their names.
e.g. libssl.so.3 (OpenSSl 3.x), libssl.so.1.1 (OpenSSL 1.1.x)
/usr/lib64/libcrypto.so.1.1.1k
/usr/lib64/libssl.so.1.1.1k
/usr/local/ncpa/libssl.so.10