OpenSSL version in Syncovery 10

English Support for Syncovery on Windows.
Post Reply
ncolvert
Posts: 2
Joined: Wed Jun 05, 2024 12:01 pm

OpenSSL version in Syncovery 10

Post by ncolvert »

Hi Tobias,

We have a client currently using Syncovery 9.50d on Windows and they have had a warning from Microsoft InTune / Defender saying that the version of OpenSSL in the Syncovery folder is 1.1.1 and has vulnerabilities as described in CVE-2023-49210, CVE-2018-16395, CVE-2017-14033 and CVE-2016-7798

Reported files
c:\program files\syncovery\libcrypto-1_1-x64.dll
c:\program files\syncovery\libssl-1_1-x64.dll

I just wanted to confirm that the OpenSSL installed with Syncovery v10 is at least 2.0.0 and not vulnerable to the issues above. Ideally it would be version 3.0.5 or above as there was a well known vulnerability in OpenSSL 3.0.4.

Assuming you can confirm the OpenSSL version installed with Syncovery is not listed as having known vulnerabilties, I will recommend to the client that they purchase Syncovery upgrade licenses for the affected PCs.

I look forward to hearing from you and thank you in advance.

Regards,

Nigel.

tobias
Posts: 1877
Joined: Tue Mar 31, 2020 7:37 pm

Re: OpenSSL version in Syncovery 10

Post by tobias »

Hello,
at this time, Syncovery 10 ships with Using OpenSSL 3.2.0 built on 23 Nov 2023.

But it also installs older SSL libraries, which are used only by the Mega connector (mega.nz). You can delete those from the program folder if you don't use Mega.

ncolvert
Posts: 2
Joined: Wed Jun 05, 2024 12:01 pm

Re: OpenSSL version in Syncovery 10

Post by ncolvert »

Thank you for the quick reply, I will pass the message along.

Regards,

Nigel.

tobias
Posts: 1877
Joined: Tue Mar 31, 2020 7:37 pm

Re: OpenSSL version in Syncovery 10

Post by tobias »

Hello,
the new version 10.15.0 now uses OpenSSL 3.3.1 only, and the Setup program will delete any older versions from the Syncovery program folder.

It has also been updated to use JQuery 3.7.1 for the browser based web GUI, which is an optional installation component.

Post Reply