Количество 21
Количество 21

CVE-2024-0727
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVE-2024-0727
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVE-2024-0727
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significan

CVE-2024-0727
CVE-2024-0727
Issue summary: Processing a maliciously formatted PKCS12 file may lead ...

SUSE-SU-2024:0842-1
Security update for openssl

SUSE-SU-2024:0841-1
Security update for openssl1

SUSE-SU-2024:0840-1
Security update for compat-openssl098

SUSE-SU-2024:0833-1
Security update for openssl-1_1

SUSE-SU-2024:0832-1
Security update for openssl-1_1

SUSE-SU-2024:0831-1
Security update for openssl-1_0_0

SUSE-SU-2024:0815-1
Security update for openssl-3

SUSE-SU-2024:0814-1
Security update for openssl-1_0_0

SUSE-SU-2024:0813-1
Security update for openssl-1_1

SUSE-SU-2024:0549-1
Security update for openssl-1_1
GHSA-9v9h-cgj8-h64p
Null pointer dereference in PKCS12 parsing

BDU:2024-01337
Уязвимость функций PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() и PKCS12_newpass() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

ROS-20240806-15
Уязвимость openssl3

SUSE-SU-2024:0518-1
Security update for openssl-3
ELSA-2024-9088
ELSA-2024-9088: edk2 security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-0727 Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant... | CVSS3: 5.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-0727 Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant... | CVSS3: 5.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-0727 Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significan | CVSS3: 5.5 | 0% Низкий | больше 1 года назад |
![]() | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-0727 Issue summary: Processing a maliciously formatted PKCS12 file may lead ... | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0842-1 Security update for openssl | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0841-1 Security update for openssl1 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0840-1 Security update for compat-openssl098 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0833-1 Security update for openssl-1_1 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0832-1 Security update for openssl-1_1 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0831-1 Security update for openssl-1_0_0 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0815-1 Security update for openssl-3 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0814-1 Security update for openssl-1_0_0 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0813-1 Security update for openssl-1_1 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:0549-1 Security update for openssl-1_1 | 0% Низкий | больше 1 года назад | |
GHSA-9v9h-cgj8-h64p Null pointer dereference in PKCS12 parsing | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
![]() | BDU:2024-01337 Уязвимость функций PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() и PKCS12_newpass() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.5 | 0% Низкий | больше 1 года назад |
![]() | ROS-20240806-15 Уязвимость openssl3 | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад |
![]() | SUSE-SU-2024:0518-1 Security update for openssl-3 | больше 1 года назад | ||
ELSA-2024-9088 ELSA-2024-9088: edk2 security update (MODERATE) | 7 месяцев назад |
Уязвимостей на страницу