Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wx7-46ch-7rq2

Опубликовано: 06 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

AES OCB fails to encrypt some bytes

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimized implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was pre-existing in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed.

Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected.

Ссылки

Пакеты

Наименование

openssl-src

rust
Затронутые версииВерсия исправления

< 111.22.0

111.22.0

Наименование

openssl-src

rust
Затронутые версииВерсия исправления

>= 300.0.0, < 300.0.9

300.0.9

EPSS

Процентиль: 67%
0.00553
Низкий

7.5 High

CVSS3

Дефекты

CWE-311
CWE-326
CWE-327

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 3 года назад

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).

CVSS3: 5.3
redhat
почти 3 года назад

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).

CVSS3: 5.3
nvd
почти 3 года назад

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).

CVSS3: 5.3
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 5.3
debian
почти 3 года назад

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimi ...

EPSS

Процентиль: 67%
0.00553
Низкий

7.5 High

CVSS3

Дефекты

CWE-311
CWE-326
CWE-327