Описание
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1.0.1-4ubuntu6 |
esm-infra-legacy/trusty | not-affected | 1.0.1-4ubuntu6 |
hardy | released | 0.9.8g-4ubuntu3.19 |
lucid | released | 0.9.8k-7ubuntu8.13 |
natty | released | 0.9.8o-5ubuntu1.7 |
oneiric | released | 1.0.0e-2ubuntu4.6 |
precise | released | 1.0.1-4ubuntu5.2 |
quantal | released | 1.0.1-4ubuntu6 |
raring | released | 1.0.1-4ubuntu6 |
saucy | released | 1.0.1-4ubuntu6 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 0.9.8o-7ubuntu4 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [0.9.8o-7ubuntu3.2.14.04.1]] |
hardy | DNE | |
lucid | DNE | |
natty | DNE | |
oneiric | ignored | end of life |
precise | released | 0.9.8o-7ubuntu3.2 |
quantal | ignored | end of life |
raring | ignored | end of life |
saucy | released | 0.9.8o-7ubuntu3.2.13.10.1 |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1 ...
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
ELSA-2012-0699: openssl security and bug fix update (MODERATE)
EPSS
6.8 Medium
CVSS2