The OpenBSD project has released a corrective update for the portable version of the LibreSSL package 3.4.2, which develops a fork of OpenSSL aimed at ensuring a higher level of security. The new version addresses a vulnerability in the X.509 certificate verification code that leads to the ignoring of errors when processing an unverified certificate chain. This issue could result in authentication bypass when validating specially crafted certificates with an incorrect trust chain.
Source: opennet.ru