Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-3733

Опубликовано: 04 мая 2017
Источник: debian
EPSS Низкий

Описание

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed1.1.0e-1package
opensslnot-affectedjessiepackage
opensslnot-affectedwheezypackage
openssl1.0not-affectedpackage

Примечания

  • https://www.openssl.org/news/secadv/20170216.txt

EPSS

Процентиль: 90%
0.05892
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

CVSS3: 5.9
redhat
почти 9 лет назад

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

CVSS3: 7.5
nvd
почти 9 лет назад

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

CVSS3: 7.5
github
больше 3 лет назад

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

CVSS3: 7.5
fstec
почти 9 лет назад

Уязвимость расширения Encrypt-Then-Mac библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 90%
0.05892
Низкий