Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-4807

Опубликовано: 08 сент. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL does not save the contents of non-volatile XMM registers on Windows 64 platform when calculating the MAC of data larger than 64 bytes. Before returning to the caller all the XMM registers are set to zero rather than restoring their previous content. The vulnerable code is used only on newer x86_64 processors supporting the AVX512-IFMA instructions. The consequences of this kind of internal application state corruption can be various - from...

РелизСтатусПримечание
bionic

not-affected

windows platform only
devel

not-affected

windows platform only
esm-apps/bionic

not-affected

windows platform only
esm-apps/xenial

not-affected

windows platform only
esm-infra/focal

not-affected

windows platform only
focal

not-affected

windows platform only
jammy

not-affected

windows platform only
lunar

not-affected

windows platform only
mantic

not-affected

windows platform only
noble

not-affected

windows platform only

Показывать по

РелизСтатусПримечание
bionic

not-affected

uses system openssl1.0
devel

not-affected

uses system openssl
esm-apps/bionic

not-affected

windows platform only
esm-apps/focal

not-affected

windows platform only
esm-apps/jammy

not-affected

windows platform only
esm-apps/noble

not-affected

uses system openssl
esm-apps/xenial

not-affected

windows platform only
esm-infra-legacy/trusty

not-affected

uses system openssl
focal

not-affected

uses system openssl
jammy

not-affected

windows platform only

Показывать по

РелизСтатусПримечание
bionic

not-affected

windows platform only
devel

not-affected

windows platform only
esm-infra-legacy/trusty

not-affected

windows platform only
esm-infra/bionic

not-affected

windows platform only
esm-infra/focal

not-affected

windows platform only
esm-infra/xenial

not-affected

windows platform only
fips-updates/bionic

not-affected

windows platform only
fips-updates/focal

not-affected

windows platform only
fips-updates/xenial

not-affected

windows platform only
fips/bionic

not-affected

windows platform only

Показывать по

РелизСтатусПримечание
bionic

not-affected

windows platform only
devel

DNE

esm-infra/bionic

not-affected

windows platform only
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

trusty

DNE

Показывать по

EPSS

Процентиль: 80%
0.01436
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
почти 2 года назад

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL does not save the contents of non-volatile XMM registers on Windows 64 platform when calculating the MAC of data larger than 64 bytes. Before returning to the caller all the XMM registers are set to zero rather than restoring their previous content. The vulnerable code is used only on newer x86_64 processors supporting the AVX512-IFMA instructions. The consequences of this kind of internal application state corruption can be various - from...

CVSS3: 7.8
nvd
почти 2 года назад

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL does not save the contents of non-volatile XMM registers on Windows 64 platform when calculating the MAC of data larger than 64 bytes. Before returning to the caller all the XMM registers are set to zero rather than restoring their previous content. The vulnerable code is used only on newer x86_64 processors supporting the AVX512-IFMA instructions. The consequences of this kind of internal application state corruption can be various - from

CVSS3: 7.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 2 года назад

Issue summary: The POLY1305 MAC (message authentication code) implemen ...

CVSS3: 7.8
redos
почти 2 года назад

Уязвимость OpenSSL

EPSS

Процентиль: 80%
0.01436
Низкий

7.8 High

CVSS3

Уязвимость CVE-2023-4807