Количество 51
Количество 51
BDU:2023-00665
Уязвимость функции GENERAL_NAME_cmp библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании
ALT-PU-2023-6515
ALT-PU-2023-6515: package `sssd` update to version 2.9.2-alt1
ALT-PU-2023-6187
ALT-PU-2023-6187: package `sssd` update to version 2.9.2-alt1
ALT-PU-2023-1221
ALT-PU-2023-1221: package `LibreSSL` update to version 3.6.2-alt1
ROS-20230620-06
Множественные уязвимости python3-cryptography
ROS-20230418-05
Множественные уязвимости OpenSSL
ALT-PU-2023-4398
ALT-PU-2023-4398: package `LibreSSL` update to version 3.7.3-alt1
ALT-PU-2023-1228
ALT-PU-2023-1228: package `openssl1.1` update to version 1.1.1t-alt1
ALT-PU-2023-1195
ALT-PU-2023-1195: package `openssl1.1` update to version 1.1.1t-alt1
ALT-PU-2024-2511
ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1
CVE-2023-0286
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ...
CVE-2023-0286
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ...
CVE-2023-0286
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ap
CVE-2023-0286
X.400 address type confusion in X.509 GeneralName
CVE-2023-0286
There is a type confusion vulnerability relating to X.400 address proc ...
SUSE-SU-2023:0482-1
Security update for openssl-1_1-livepatches
RLSA-2025:7937
Important: compat-openssl11 security update
RLSA-2025:7895
Important: compat-openssl10 security update
GHSA-x4qr-2fvf-3mr5
Vulnerable OpenSSL included in cryptography wheels
ELSA-2025-7937
ELSA-2025-7937: compat-openssl11 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2023-00665 Уязвимость функции GENERAL_NAME_cmp библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.4 | 60% Средний | больше 3 лет назад | |
ALT-PU-2023-6515 ALT-PU-2023-6515: package `sssd` update to version 2.9.2-alt1 | CVSS3: 7.4 | 60% Средний | почти 3 года назад | |
ALT-PU-2023-6187 ALT-PU-2023-6187: package `sssd` update to version 2.9.2-alt1 | CVSS3: 7.4 | 60% Средний | почти 3 года назад | |
ALT-PU-2023-1221 ALT-PU-2023-1221: package `LibreSSL` update to version 3.6.2-alt1 | CVSS3: 7.4 | 60% Средний | больше 3 лет назад | |
ROS-20230620-06 Множественные уязвимости python3-cryptography | CVSS3: 9.1 | больше 3 лет назад | ||
ROS-20230418-05 Множественные уязвимости OpenSSL | CVSS3: 7.5 | больше 3 лет назад | ||
ALT-PU-2023-4398 ALT-PU-2023-4398: package `LibreSSL` update to version 3.7.3-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-1228 ALT-PU-2023-1228: package `openssl1.1` update to version 1.1.1t-alt1 | CVSS3: 7.5 | больше 3 лет назад | ||
ALT-PU-2023-1195 ALT-PU-2023-1195: package `openssl1.1` update to version 1.1.1t-alt1 | CVSS3: 7.5 | больше 3 лет назад | ||
ALT-PU-2024-2511 ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1 | CVSS3: 9.8 | больше 2 лет назад | ||
CVE-2023-0286 There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ... | CVSS3: 7.4 | 60% Средний | больше 3 лет назад | |
CVE-2023-0286 There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ... | CVSS3: 7.4 | 60% Средний | больше 3 лет назад | |
CVE-2023-0286 There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect ap | CVSS3: 7.4 | 60% Средний | больше 3 лет назад | |
CVE-2023-0286 X.400 address type confusion in X.509 GeneralName | CVSS3: 7.4 | 60% Средний | 8 месяцев назад | |
CVE-2023-0286 There is a type confusion vulnerability relating to X.400 address proc ... | CVSS3: 7.4 | 60% Средний | больше 3 лет назад | |
SUSE-SU-2023:0482-1 Security update for openssl-1_1-livepatches | 60% Средний | больше 3 лет назад | ||
RLSA-2025:7937 Important: compat-openssl11 security update | 60% Средний | около 1 года назад | ||
RLSA-2025:7895 Important: compat-openssl10 security update | 60% Средний | около 1 года назад | ||
GHSA-x4qr-2fvf-3mr5 Vulnerable OpenSSL included in cryptography wheels | CVSS3: 7.4 | 60% Средний | больше 3 лет назад | |
ELSA-2025-7937 ELSA-2025-7937: compat-openssl11 security update (IMPORTANT) | 60% Средний | больше 1 года назад |
Уязвимостей на страницу