Количество 51
Количество 51
BDU:2022-01315
Уязвимость функции BN_mod_sqrt() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20220318-02
Уязвимость библиотеки OpenSSL
ALT-PU-2022-2174
ALT-PU-2022-2174: package `mysql-connector-odbc` update to version 8.0.29-alt1
ALT-PU-2022-2167
ALT-PU-2022-2167: package `mysql-connector-odbc` update to version 8.0.29-alt1
ALT-PU-2022-1489
ALT-PU-2022-1489: package `openssl1.1` update to version 1.1.1n-alt1
ALT-PU-2022-1515
ALT-PU-2022-1515: package `openssl1.1` update to version 1.1.1n-alt1
ALT-PU-2022-1799
ALT-PU-2022-1799: package `node` update to version 14.19.1-alt1
ALT-PU-2022-1760
ALT-PU-2022-1760: package `node` update to version 16.14.2-alt1
ALT-PU-2023-1461
ALT-PU-2023-1461: package `node` update to version 16.18.1-alt1
CVE-2022-0778
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities...
CVE-2022-0778
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities...
CVE-2022-0778
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities pa
CVE-2022-0778
CVE-2022-0778
The BN_mod_sqrt() function, which computes a modular square root, cont ...
openSUSE-SU-2022:0856-1
Security update for openssl-1_0_0
SUSE-SU-2022:14916-1
Security update for openssl1
SUSE-SU-2022:14915-1
Security update for openssl
SUSE-SU-2022:0935-1
Security update for nodejs12
SUSE-SU-2022:0860-1
Security update for openssl-1_1
SUSE-SU-2022:0859-1
Security update for compat-openssl098
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2022-01315 Уязвимость функции BN_mod_sqrt() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 73% Высокий | больше 4 лет назад | |
ROS-20220318-02 Уязвимость библиотеки OpenSSL | 73% Высокий | больше 4 лет назад | ||
ALT-PU-2022-2174 ALT-PU-2022-2174: package `mysql-connector-odbc` update to version 8.0.29-alt1 | CVSS3: 7.5 | 73% Высокий | около 4 лет назад | |
ALT-PU-2022-2167 ALT-PU-2022-2167: package `mysql-connector-odbc` update to version 8.0.29-alt1 | CVSS3: 7.5 | 73% Высокий | около 4 лет назад | |
ALT-PU-2022-1489 ALT-PU-2022-1489: package `openssl1.1` update to version 1.1.1n-alt1 | CVSS3: 7.5 | 73% Высокий | больше 4 лет назад | |
ALT-PU-2022-1515 ALT-PU-2022-1515: package `openssl1.1` update to version 1.1.1n-alt1 | CVSS3: 7.5 | больше 4 лет назад | ||
ALT-PU-2022-1799 ALT-PU-2022-1799: package `node` update to version 14.19.1-alt1 | CVSS3: 8.2 | больше 4 лет назад | ||
ALT-PU-2022-1760 ALT-PU-2022-1760: package `node` update to version 16.14.2-alt1 | CVSS3: 8.2 | больше 4 лет назад | ||
ALT-PU-2023-1461 ALT-PU-2023-1461: package `node` update to version 16.18.1-alt1 | CVSS3: 9.8 | больше 3 лет назад | ||
CVE-2022-0778 The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities... | CVSS3: 7.5 | 73% Высокий | больше 4 лет назад | |
CVE-2022-0778 The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities... | CVSS3: 7.5 | 73% Высокий | больше 4 лет назад | |
CVE-2022-0778 The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities pa | CVSS3: 7.5 | 73% Высокий | больше 4 лет назад | |
CVSS3: 7.5 | 73% Высокий | больше 4 лет назад | ||
CVE-2022-0778 The BN_mod_sqrt() function, which computes a modular square root, cont ... | CVSS3: 7.5 | 73% Высокий | больше 4 лет назад | |
openSUSE-SU-2022:0856-1 Security update for openssl-1_0_0 | 73% Высокий | больше 4 лет назад | ||
SUSE-SU-2022:14916-1 Security update for openssl1 | 73% Высокий | больше 4 лет назад | ||
SUSE-SU-2022:14915-1 Security update for openssl | 73% Высокий | больше 4 лет назад | ||
SUSE-SU-2022:0935-1 Security update for nodejs12 | 73% Высокий | больше 4 лет назад | ||
SUSE-SU-2022:0860-1 Security update for openssl-1_1 | 73% Высокий | больше 4 лет назад | ||
SUSE-SU-2022:0859-1 Security update for compat-openssl098 | 73% Высокий | больше 4 лет назад |
Уязвимостей на страницу