You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Could you confirm if this issue has been addressed in the latest version of the OCS Agent? If not, is there an update planned to replace the affected DLL?
Thank you for your assistance.
Best regards,
The text was updated successfully, but these errors were encountered:
After investigating the issue, it doesn't seems we use the impacted function in our agent.
Nonetheless, we are going to provide an updated agent with openssl 1.0.2zd.
Thank you for your prompt response and for investigating the issue. I appreciate your efforts in planning to update the agent with OpenSSL 1.0.2zd.
Given that the impacted function isn't utilized in the agent, would it be feasible to remove the vulnerable DLL entirely? This could potentially simplify the codebase and eliminate any associated security risks.
Thank you once again for your attention to this matter.
Hello OCS Inventory Team,
We have identified that the OCS Inventory Agent includes a vulnerable version of
ssleay32.dll
in its installation folder:C:\Program Files\OCS Inventory Agent\ssleay32.dll
1.0.2r
>= 1.0.2, < 1.0.2zd
)Could you confirm if this issue has been addressed in the latest version of the OCS Agent? If not, is there an update planned to replace the affected DLL?
Thank you for your assistance.
Best regards,
The text was updated successfully, but these errors were encountered: