Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-0739

Опубликовано: 27 мар. 2018
Источник: redhat
CVSS3: 6.5

Описание

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5opensslOut of support scope
Red Hat Enterprise Linux 5openssl097aOut of support scope
Red Hat Enterprise Linux 6opensslWill not fix
Red Hat Enterprise Linux 6openssl098eWill not fix
Red Hat Enterprise Linux 7openssl098eWill not fix
Red Hat Enterprise Linux 7OVMFWill not fix
Red Hat Enterprise Linux 8opensslNot affected
Red Hat JBoss Enterprise Application Platform 5opensslWill not fix
Red Hat JBoss Enterprise Application Platform 6opensslWill not fix
Red Hat JBoss Enterprise Web Server 2opensslWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1561266openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

CVSS3: 6.5
nvd
около 7 лет назад

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

CVSS3: 6.5
debian
около 7 лет назад

Constructed ASN.1 types with a recursive definition (such as can be fo ...

suse-cvrf
почти 7 лет назад

Security update for ovmf

suse-cvrf
почти 7 лет назад

Security update for ovmf

6.5 Medium

CVSS3