Логотип exploitDog
bind: "CVE-2024-0727"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-0727"

Количество 21

Количество 21

ubuntu логотип

CVE-2024-0727

больше 1 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2024-0727

больше 1 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-0727

больше 1 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significan

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-0727

больше 1 года назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-0727

больше 1 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead ...

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0842-1

больше 1 года назад

Security update for openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0841-1

больше 1 года назад

Security update for openssl1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0840-1

больше 1 года назад

Security update for compat-openssl098

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0833-1

больше 1 года назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0832-1

больше 1 года назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0831-1

больше 1 года назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0815-1

больше 1 года назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0814-1

больше 1 года назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0813-1

больше 1 года назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0549-1

больше 1 года назад

Security update for openssl-1_1

EPSS: Низкий
github логотип

GHSA-9v9h-cgj8-h64p

больше 1 года назад

Null pointer dereference in PKCS12 parsing

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2024-01337

больше 1 года назад

Уязвимость функций PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() и PKCS12_newpass() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
EPSS: Низкий
redos логотип

ROS-20240806-15

11 месяцев назад

Уязвимость openssl3

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0518-1

больше 1 года назад

Security update for openssl-3

EPSS: Низкий
oracle-oval логотип

ELSA-2024-9088

7 месяцев назад

ELSA-2024-9088: edk2 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significan

CVSS3: 5.5
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0842-1

Security update for openssl

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0841-1

Security update for openssl1

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0840-1

Security update for compat-openssl098

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0833-1

Security update for openssl-1_1

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0832-1

Security update for openssl-1_1

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0831-1

Security update for openssl-1_0_0

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0815-1

Security update for openssl-3

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0814-1

Security update for openssl-1_0_0

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0813-1

Security update for openssl-1_1

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0549-1

Security update for openssl-1_1

0%
Низкий
больше 1 года назад
github логотип
GHSA-9v9h-cgj8-h64p

Null pointer dereference in PKCS12 parsing

CVSS3: 5.5
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-01337

Уязвимость функций PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() и PKCS12_newpass() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240806-15

Уязвимость openssl3

CVSS3: 5.5
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:0518-1

Security update for openssl-3

больше 1 года назад
oracle-oval логотип
ELSA-2024-9088

ELSA-2024-9088: edk2 security update (MODERATE)

7 месяцев назад

Уязвимостей на страницу