Количество 34
Количество 34

ROS-20230621-05
Уязвимость Openssl
GHSA-gqxg-9vfr-p9cg
Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time....

BDU:2023-03652
Уязвимость библиотеки OpenSSL, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

SUSE-SU-2023:2234-1
Security update for ovmf

SUSE-SU-2023:1968-1
Security update for ovmf

SUSE-SU-2023:1958-1
Security update for ovmf

SUSE-SU-2023:1941-1
Security update for ovmf

SUSE-SU-2023:1940-1
Security update for ovmf

SUSE-SU-2023:1921-1
Security update for ovmf

SUSE-SU-2023:29171-1
Security update for openssl-1_1

SUSE-SU-2023:2620-1
Security update for openssl-3

SUSE-SU-2023:2470-1
Security update for openssl-3
ELSA-2023-3722
ELSA-2023-3722: openssl security and bug fix update (MODERATE)
ELSA-2023-12768
ELSA-2023-12768: openssl security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | ROS-20230621-05 Уязвимость Openssl | CVSS3: 7.5 | 88% Высокий | около 2 лет назад |
GHSA-gqxg-9vfr-p9cg Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time.... | CVSS3: 7.5 | 88% Высокий | около 2 лет назад | |
![]() | BDU:2023-03652 Уязвимость библиотеки OpenSSL, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 88% Высокий | около 2 лет назад |
![]() | SUSE-SU-2023:2234-1 Security update for ovmf | около 2 лет назад | ||
![]() | SUSE-SU-2023:1968-1 Security update for ovmf | больше 2 лет назад | ||
![]() | SUSE-SU-2023:1958-1 Security update for ovmf | больше 2 лет назад | ||
![]() | SUSE-SU-2023:1941-1 Security update for ovmf | больше 2 лет назад | ||
![]() | SUSE-SU-2023:1940-1 Security update for ovmf | больше 2 лет назад | ||
![]() | SUSE-SU-2023:1921-1 Security update for ovmf | больше 2 лет назад | ||
![]() | SUSE-SU-2023:29171-1 Security update for openssl-1_1 | около 2 лет назад | ||
![]() | SUSE-SU-2023:2620-1 Security update for openssl-3 | около 2 лет назад | ||
![]() | SUSE-SU-2023:2470-1 Security update for openssl-3 | около 2 лет назад | ||
ELSA-2023-3722 ELSA-2023-3722: openssl security and bug fix update (MODERATE) | около 2 лет назад | |||
ELSA-2023-12768 ELSA-2023-12768: openssl security update (IMPORTANT) | почти 2 года назад |
Уязвимостей на страницу