Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-01223

Опубликовано: 11 сент. 2025
Источник: fstec
CVSS3: 6.1
CVSS2: 5.7
EPSS Низкий

Описание

Уязвимость файлов формата PKCS#12 библиотеки OpenSSL связана с разыменованием указателей. Эксплуатация уязвимость может позволить нарушителю вызвать отказ в обслуживании или выпонить произвольный код

Вендор

ООО «Ред Софт»
OpenSSL Software Foundation
Node.js Foundation

Наименование ПО

РЕД ОС
OpenSSL
Node.js

Версия ПО

7.3 (РЕД ОС)
8.0 (РЕД ОС)
от 3.5 до 3.5.5 (OpenSSL)
от 3.4 до 3.4.4 (OpenSSL)
от 3.6.0 до 3.6.1 (OpenSSL)
22.22.0 (Node.js)
24.13.0 (Node.js)
25.3.0 (Node.js)

Тип ПО

Операционная система
Программное средство защиты
Сетевое программное средство

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5,7)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6,1)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
Обновление программного обеспечения до версий 3.6.1, 3.5.5 и 3.4.4:
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2025-11187
Для РедОС:
https://redos.red-soft.ru/search/?iblock_id=&q=CVE-2025-11187

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 91%
0.04517
Низкий

6.1 Medium

CVSS3

5.7 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
redos
3 месяца назад

Уязвимость openssl3

CVSS3: 6.1
ubuntu
6 месяцев назад

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations. When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference. Exploiting this issue requires a user or application to process a maliciously crafted ...

CVSS3: 6.1
redhat
6 месяцев назад

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations. When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference. Exploiting this issue requires a user or application to process a maliciously crafted ...

CVSS3: 6.1
nvd
6 месяцев назад

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations. When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2 salt and keylength parameters from the file are used without validation. If the value of keylength exceeds the size of the fixed stack buffer used for the derived key (64 bytes), the key derivation will overflow the buffer. The overflow length is attacker-controlled. Also, if the salt parameter is not an OCTET STRING type this can lead to invalid or NULL pointer dereference. Exploiting this issue requires a user or application to process a maliciously crafted

CVSS3: 6.1
debian
6 месяцев назад

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validati ...

EPSS

Процентиль: 91%
0.04517
Низкий

6.1 Medium

CVSS3

5.7 Medium

CVSS2