---
title: "CVE-2022-3786"
canonical: "https://kb.cynergy.app/space/MD/927924232/CVE-2022-3786"
format: markdown
---
**Description**

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.

**Published On**

11/01/2022

**Updated On**

11/04/2022

**Trending**

TRUE

**CWE**

<u>[CWE-120](http://cwe.mitre.org/data/definitions/120.html)</u>

**Exploit**

 

**Mitigation:**

No mitigation avaluble  

**Remediation**

- [160191](https://cve.report/qid/160191) Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2022-7288)
- [160192](https://cve.report/qid/160192) Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2022-9968)
- [199012](https://cve.report/qid/199012) Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-5710-1)
- [240798](https://cve.report/qid/240798) Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2022:7288)
- [283270](https://cve.report/qid/283270) Fedora Security Update for Open Secure Sockets Layer (OpenSSL) (FEDORA-2022-502f096dce)
- [354102](https://cve.report/qid/354102) Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2022-2022-157
- [377733](https://cve.report/qid/377733) Open Secure Sockets Layer (OpenSSL) Less Than 3.0.7 Buffer Overflow Vulnerability (Scan Utility)
- [38879](https://cve.report/qid/38879) Open Secure Sockets Layer (OpenSSL) Less Than 3.0.7 Buffer Overflow Vulnerability
- [502587](https://cve.report/qid/502587) Alpine Linux Security Update for Open Secure Sockets Layer3 (OpenSSL3)
- [520001](https://cve.report/qid/520001) Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (CVE-2022-3602, CVE-2022-3786)
- [690972](https://cve.report/qid/690972) Free Berkeley Software Distribution (FreeBSD) Security Update for Open Secure Sockets Layer (OpenSSL) (0844671c-5a09-11ed-856e-d4c9ef517024)
- [710678](https://cve.report/qid/710678) Gentoo Linux Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (GLSA 202211-01)
- [752752](https://cve.report/qid/752752) SUSE Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL-3) (SUSE-SU-2022:3843-1)
- [940723](https://cve.report/qid/940723) AlmaLinux Security Update for Open Secure Sockets Layer (OpenSSL) (ALSA-2022:7288)

**References**


[http://www.openssl.org](http://www.openssl.org)   
<span style="color: #ffffff">**text/plain**</span>  
[CONFIRM www.openssl.org/news/secadv/20221101.txt](https://cve.report/CVE-2022-3786/2447d18c)oss-security - Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/9)oss-security - Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221103 Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/03/3)[http://git.openssl.org](http://git.openssl.org)  Git

![URL Logo]()

[http://git.openssl.org](http://git.openssl.org)   
<span style="color: #ffffff">**text/xml**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span>  
[MISC git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=c42165b5706e42f67ef8ef4c351a9a4c5d21639a](https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=c42165b5706e42f67ef8ef4c351a9a4c5d21639a)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/18)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/5)[SECURITY] Fedora 36 Update: openssl-3.0.5-2.fc36 - package-announce - Fedora Mailing-Lists

![URL Logo]()

[http://lists.fedoraproject.org](http://lists.fedoraproject.org)   
<span style="color: #ffffff">**text/html**</span>  
[MISC lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63YRPWPUSX3MBHNPIEJZDKQT6YA7UF6S/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63YRPWPUSX3MBHNPIEJZDKQT6YA7UF6S/)Security Advisory

![URL Logo]()

<span style="color: #ffffff">**[psirt.global.sonicwall.com](http://psirt.global.sonicwall.com)**</span>  
<span style="color: #ffffff">**text/html**</span>  
[CONFIRM psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0023](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0023)

![URL Logo]()

<span style="color: #ffffff">**No Description **</span><span style="color: #ffffff">**[Providedtools.cisco.com](http://Providedtools.cisco.com)**</span>  
<span style="color: #ffffff">**text/html**</span>  
[CISCO 20221028 Vulnerabilities in OpenSSL Affecting Cisco Products: November 2022](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-W9sdCc2a)OpenSSL: Multiple Vulnerabilities (GLSA 202211-01) — Gentoo security

![URL Logo]()

[http://security.gentoo.org](http://security.gentoo.org)   
<span style="color: #ffffff">**text/html**</span>  
[GENTOO GLSA-202211-01](https://security.gentoo.org/glsa/202211-01)VU#794340 - OpenSSL 3.0.0 to 3.0.6 decodes some punycode email addresses in X.509 certificates improperly

![URL Logo]()

[http://www.kb.cert.org](http://www.kb.cert.org)   
<span style="color: #ffffff">**text/html**</span>  
[CERT-VN VU#794340](https://www.kb.cert.org/vuls/id/794340)oss-security - Re: Fwd: Node.js security updates for all active release lines, November 2022

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: Fwd: Node.js security updates for all active release lines, November 2022](https://www.openwall.com/lists/oss-security/2022/11/02/10)oss-security - Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/14)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/16)[SECURITY] Fedora 37 Update: openssl-3.0.5-3.fc37 - package-announce - Fedora Mailing-Lists

![URL Logo]()

[http://lists.fedoraproject.org](http://lists.fedoraproject.org)   
<span style="color: #ffffff">**text/html**</span>  
[MISC lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWP23EZYOBDJQP7HP4YU7W2ABU2YDITS/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWP23EZYOBDJQP7HP4YU7W2ABU2YDITS/)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/1)OpenSSL Security Advisory 20221101 ≈ Packet Storm

![URL Logo]()

[http://packetstormsecurity.com](http://packetstormsecurity.com)   
<span style="color: #ffffff">**text/html**</span>  
[http://packetstormsecurity.com/files/169687/OpenSSL-Security-Advisory-20221101.html](http://packetstormsecurity.com/files/169687/OpenSSL-Security-Advisory-20221101.html) oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/19)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/13)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/17)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/03/1)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/7)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/2)November 2022 OpenSSL Vulnerabilities in NetApp Products | NetApp Product Security

![URL Logo]()

[http://security.netapp.com](http://security.netapp.com)   
<span style="color: #ffffff">**text/html**</span>  
[CONFIRM security.netapp.com/advisory/ntap-20221102-0001/](https://security.netapp.com/advisory/ntap-20221102-0001/)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MISC www.openwall.com/lists/oss-security/2022/11/03/10](https://www.openwall.com/lists/oss-security/2022/11/03/10)oss-security - Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MISC www.openwall.com/lists/oss-security/2022/11/03/9](https://www.openwall.com/lists/oss-security/2022/11/03/9)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/24)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221103 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/03/5)oss-security - Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221103 Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/03/6)oss-security - OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/15)oss-security - Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/12)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/20)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/03/2)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/3)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/6)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/02/15)oss-security - Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221103 Re: Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/03/7)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MISC www.openwall.com/lists/oss-security/2022/11/03/11](https://www.openwall.com/lists/oss-security/2022/11/03/11)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/x-c**</span>  
[MLIST [oss-security] 20221102 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://cve.report/CVE-2022-3786/5af7b82d)oss-security - Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)

![URL Logo]()

[http://www.openwall.com](http://www.openwall.com)   
<span style="color: #ffffff">**text/html**</span>  
[MLIST [oss-security] 20221101 Re: OpenSSL X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602), X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)](https://www.openwall.com/lists/oss-security/2022/11/01/21)

![URL Logo]()