Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 21, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 21, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 21, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 21, 2025

      Google DeepMind’s CEO says Gemini’s upgrades could lead to AGI — but he still thinks society isn’t “ready for it”

      May 21, 2025

      Windows 11 is getting AI Actions in File Explorer — here’s how to try them right now

      May 21, 2025

      Is The Alters on Game Pass?

      May 21, 2025

      I asked Copilot’s AI to predict the outcome of the Europa League final, and now I’m just sad

      May 21, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Celebrating GAAD by Committing to Universal Design: Equitable Use

      May 21, 2025
      Recent

      Celebrating GAAD by Committing to Universal Design: Equitable Use

      May 21, 2025

      GAAD and Universal Design in Healthcare – A Deeper Look

      May 21, 2025

      GAAD and Universal Design in Pharmacy – A Deeper Look

      May 21, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Google DeepMind’s CEO says Gemini’s upgrades could lead to AGI — but he still thinks society isn’t “ready for it”

      May 21, 2025
      Recent

      Google DeepMind’s CEO says Gemini’s upgrades could lead to AGI — but he still thinks society isn’t “ready for it”

      May 21, 2025

      Windows 11 is getting AI Actions in File Explorer — here’s how to try them right now

      May 21, 2025

      Is The Alters on Game Pass?

      May 21, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-4575 – OpenSSL -addreject Option Truncation Vulnerability

    CVE-2025-4575 – OpenSSL -addreject Option Truncation Vulnerability

    May 22, 2025

    CVE ID : CVE-2025-4575

    Published : May 22, 2025, 2:16 p.m. | 2 hours, 30 minutes ago

    Description : Issue summary: Use of -addreject option with the openssl x509 application adds
    a trusted use instead of a rejected use for a certificate.

    Impact summary: If a user intends to make a trusted certificate rejected for
    a particular use it will be instead marked as trusted for that use.

    A copy & paste error during minor refactoring of the code introduced this
    issue in the OpenSSL 3.5 version. If, for example, a trusted CA certificate
    should be trusted only for the purpose of authenticating TLS servers but not
    for CMS signature verification and the CMS signature verification is intended
    to be marked as rejected with the -addreject option, the resulting CA
    certificate will be trusted for CMS signature verification purpose instead.

    Only users which use the trusted certificate format who use the openssl x509
    command line application to add rejected uses are affected by this issue.
    The issues affecting only the command line application are considered to
    be Low severity.

    Hostinger

    The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this
    issue.

    OpenSSL 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1 and 1.0.2 are also not affected by this
    issue.

    Severity: 6.5 | MEDIUM

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-4979 – GitLab Information Disclosure Vulnerability
    Next Article CVE-2025-3111 – GitLab Kubernetes Denial of Service Vulnerability

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 22, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2024-13953 – Raritan ASPECT Device Logger Credential Exposure Vulnerability

    May 22, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Content-Adaptive Tokenizer (CAT): An Image Tokenizer that Adapts Token Count based on Image Complexity, Offering Flexible 8x, 16x, or 32x Compression

    Machine Learning

    How to Disable ‘App is Ready’ Notifications in Ubuntu

    Linux

    Title Launch Observability at Netflix Scale

    Development

    Free Decryptor Released for BitLocker-Based ShrinkLocker Ransomware Victims

    Development

    Highlights

    Development

    Build generative AI applications on Amazon Bedrock with the AWS SDK for Python (Boto3)

    November 22, 2024

    Amazon Bedrock is a fully managed service that offers a choice of high-performing foundation models…

    Bitwarden CLI – access and manage your vault

    April 11, 2025

    EU Chat Control Proposal to Prevent Child Sexual Abuse Slammed by Critics

    June 18, 2024

    MoMA: An Open-Vocabulary and Training Free Personalized Image Model that Boasts Flexible Zero-Shot Capabilities

    April 12, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.