Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-0733

Опубликовано: 27 мар. 2018
Источник: debian
EPSS Низкий

Описание

Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed1.1.0h-1package
opensslfixed1.1.0f-3+deb9u2stretchpackage
opensslnot-affectedjessiepackage
opensslnot-affectedwheezypackage
openssl1.0not-affectedpackage

Примечания

  • Issue specific to HP-UX

  • https://www.openssl.org/news/secadv/20180327.txt

EPSS

Процентиль: 83%
0.01955
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 8 лет назад

Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).

CVSS3: 4.8
redhat
почти 8 лет назад

Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).

CVSS3: 5.9
nvd
почти 8 лет назад

Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).

CVSS3: 5.9
github
больше 3 лет назад

Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).

CVSS3: 5.9
fstec
почти 8 лет назад

Уязвимость функции PA-RISC CRYPTO_memcmp библиотеки OpenSSL, позволяющая нарушителю формировать поддельные сообщения

EPSS

Процентиль: 83%
0.01955
Низкий