a small and plucky upstart with a meager $20 billion market cap just can’t focus on such complex and unnecessary items such as security of their products and customer data. the budget and manpower just isn’t there.
This is getting ridiculous. This issue is NOT RESOLVED Keeping OpenSSL libraries current is a trivial but critical task and this makes Zoom look like an absolute joke to the Enterprise IT industry. You all realize that Zoom is at the top of every vulnerability dashboard in large organizations because of these vulns? Fix your software or pay the price in lost enterprise customers.
6.2.0 update is out. guess what didn’t get fixed yet again? and of course why would it, we’ve seen how much priority this company places on this kind of stuff.
they probably need some more bad PR like they got at the start of Covid to actually pretend to put in some work again until things cool down.
Yep, still showing as vulnerable.
c:\program files (x86)\zoom\zoom outlook plugin\libcrypto-3-zm.dll
c:\program files (x86)\zoom\zoom out
c:\program files\zoom\bin\libcrypto-3-zm.dll
c:\program files\zoom\bin\libssl-3-zm.dll
c:\program files\zoomrooms\bin\libcrypto-3-zm.dll
c:\program files\zoomrooms\bin\libssl-3-zm.dll
c:\program files (x86)\zoom\bin\libcrypto-3-zm.dll
c:\program files (x86)\zoom\bin\libssl-3-zm.dll
c:\program files (x86)\zoom\zoom outlook plugin\libcrypto-3-zm.dll
c:\program files (x86)\zoom\zoom outlook plugin\x64\libcrypto-3-zm.dll
Just upgraded to Zoom 6.2.2.47417 and now finally libcrypto-3-zm.dll and libssl-3-zm.dll show as version 3.1.7.
Relief.