Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-4228

Опубликовано: 26 сент. 2018
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2018-4228: openssl security update (IMPORTANT)

[1.0.1e-57.0.5]

  • Merge upstream patch to fix CVE-2018-0739

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

openssl

1.0.1e-57.0.5.el6

openssl-devel

1.0.1e-57.0.5.el6

openssl-perl

1.0.1e-57.0.5.el6

openssl-static

1.0.1e-57.0.5.el6

Oracle Linux i686

openssl

1.0.1e-57.0.5.el6

openssl-devel

1.0.1e-57.0.5.el6

openssl-perl

1.0.1e-57.0.5.el6

openssl-static

1.0.1e-57.0.5.el6

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

CVSS3: 6.5
redhat
около 7 лет назад

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

CVSS3: 6.5
nvd
около 7 лет назад

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

CVSS3: 6.5
debian
около 7 лет назад

Constructed ASN.1 types with a recursive definition (such as can be fo ...

suse-cvrf
почти 7 лет назад

Security update for ovmf