Improper certificate validation in PKCS7_verify() in AWS-LC allows an
unauthenticated user to bypass certificate chain verification when processing
PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. aws-lc-sys contains
code from AWS-LC. Applications using aws-lc-sys should upgrade to the most
recent release of aws-lc-sys.
There is no workaround; applications using aws-lc-sys should upgrade to the
most recent release of aws-lc-sys.
aws-lc-sys0.37.0Improper certificate validation in
PKCS7_verify()in AWS-LC allows anunauthenticated user to bypass certificate chain verification when processing
PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action.
aws-lc-syscontainscode from AWS-LC. Applications using
aws-lc-sysshould upgrade to the mostrecent release of
aws-lc-sys.There is no workaround; applications using
aws-lc-sysshould upgrade to themost recent release of aws-lc-sys.