Описание
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
An out of bounds write flaw was discovered in the OpenSSL BN_bn2dec() function. An attacker able to make an application using OpenSSL to process a large BIGNUM could cause the application to crash or, possibly, execute arbitrary code.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | openssl | Will not fix | ||
Red Hat Enterprise Linux 5 | openssl097a | Will not fix | ||
Red Hat Enterprise Linux 6 | openssl098e | Will not fix | ||
Red Hat Enterprise Linux 7 | openssl098e | Will not fix | ||
Red Hat JBoss Enterprise Application Platform 6 | openssl | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | openssl | Will not fix | ||
Red Hat JBoss Enterprise Web Server 2 | openssl | Will not fix | ||
Red Hat JBoss Enterprise Web Server 3 | openssl | Fix deferred | ||
JBoss Core Services on RHEL 6 | jbcs-httpd24-apache-commons-daemon | Fixed | RHSA-2018:2186 | 12.07.2018 |
JBoss Core Services on RHEL 6 | jbcs-httpd24-apache-commons-daemon-jsvc | Fixed | RHSA-2018:2186 | 12.07.2018 |
Показывать по
Дополнительная информация
Статус:
6.2 Medium
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 ...
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
Уязвимость библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
6.2 Medium
CVSS3
4.3 Medium
CVSS2