Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

oracle-oval Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

ELSA-2023-12210

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 22 ΠΌΠ°Ρ€. 2023
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: oracle-oval
ΠŸΠ»Π°Ρ‚Ρ„ΠΎΡ€ΠΌΠ°: Oracle Linux 7

ОписаниС

ELSA-2023-12210: openssl security update (IMPORTANT)

[1:1.0.2k-26]

  • Fixes CVE-2023-0286 X.400 address type confusion in X.509 GeneralName
  • Resolves: rhbz#2176790

ΠžΠ±Π½ΠΎΠ²Π»Π΅Π½Π½Ρ‹Π΅ ΠΏΠ°ΠΊΠ΅Ρ‚Ρ‹

Oracle Linux 7

Oracle Linux aarch64

openssl

1.0.2k-26.ksplice1.el7_9

openssl-devel

1.0.2k-26.ksplice1.el7_9

openssl-libs

1.0.2k-26.ksplice1.el7_9

openssl-perl

1.0.2k-26.ksplice1.el7_9

openssl-static

1.0.2k-26.ksplice1.el7_9

Oracle Linux x86_64

openssl

1.0.2k-26.ksplice1.el7_9

openssl-devel

1.0.2k-26.ksplice1.el7_9

openssl-libs

1.0.2k-26.ksplice1.el7_9

openssl-perl

1.0.2k-26.ksplice1.el7_9

openssl-static

1.0.2k-26.ksplice1.el7_9

БвязанныС CVE

Бсылки Π½Π° источники

БвязанныС уязвимости

CVSS3: 7.4
ubuntu
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ...

CVSS3: 7.4
redhat
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ...

CVSS3: 7.4
nvd
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ap

CVSS3: 7.4
msrc
6 мСсяцСв Π½Π°Π·Π°Π΄

X.400 address type confusion in X.509 GeneralName

CVSS3: 7.4
debian
большС 3 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

There is a type confusion vulnerability relating to X.400 address proc ...

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ ELSA-2023-12210