Hi Tobias,
We have a client currently using Syncovery 9.50d on Windows and they have had a warning from Microsoft InTune / Defender saying that the version of OpenSSL in the Syncovery folder is 1.1.1 and has vulnerabilities as described in CVE-2023-49210, CVE-2018-16395, CVE-2017-14033 and CVE-2016-7798
Reported files
c:\program files\syncovery\libcrypto-1_1-x64.dll
c:\program files\syncovery\libssl-1_1-x64.dll
I just wanted to confirm that the OpenSSL installed with Syncovery v10 is at least 2.0.0 and not vulnerable to the issues above. Ideally it would be version 3.0.5 or above as there was a well known vulnerability in OpenSSL 3.0.4.
Assuming you can confirm the OpenSSL version installed with Syncovery is not listed as having known vulnerabilties, I will recommend to the client that they purchase Syncovery upgrade licenses for the affected PCs.
I look forward to hearing from you and thank you in advance.
Regards,
Nigel.
OpenSSL version in Syncovery 10
Re: OpenSSL version in Syncovery 10
Hello,
at this time, Syncovery 10 ships with Using OpenSSL 3.2.0 built on 23 Nov 2023.
But it also installs older SSL libraries, which are used only by the Mega connector (mega.nz). You can delete those from the program folder if you don't use Mega.
at this time, Syncovery 10 ships with Using OpenSSL 3.2.0 built on 23 Nov 2023.
But it also installs older SSL libraries, which are used only by the Mega connector (mega.nz). You can delete those from the program folder if you don't use Mega.
Re: OpenSSL version in Syncovery 10
Thank you for the quick reply, I will pass the message along.
Regards,
Nigel.
Regards,
Nigel.
Re: OpenSSL version in Syncovery 10
Hello,
the new version 10.15.0 now uses OpenSSL 3.3.1 only, and the Setup program will delete any older versions from the Syncovery program folder.
It has also been updated to use JQuery 3.7.1 for the browser based web GUI, which is an optional installation component.
the new version 10.15.0 now uses OpenSSL 3.3.1 only, and the Setup program will delete any older versions from the Syncovery program folder.
It has also been updated to use JQuery 3.7.1 for the browser based web GUI, which is an optional installation component.