Логотип exploitDog
bind:"BDU:2023-03652" OR bind:"CVE-2023-2650"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2023-03652" OR bind:"CVE-2023-2650"

Количество 24

Количество 24

fstec логотип

BDU:2023-03652

около 2 лет назад

Уязвимость библиотеки OpenSSL, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Критический
ubuntu логотип

CVE-2023-2650

около 2 лет назад

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time. The...

CVSS3: 6.5
EPSS: Критический
redhat логотип

CVE-2023-2650

около 2 лет назад

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time. T...

CVSS3: 6.5
EPSS: Критический
nvd логотип

CVE-2023-2650

около 2 лет назад

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time. T

CVSS3: 6.5
EPSS: Критический
msrc логотип

CVE-2023-2650

около 2 лет назад

CVSS3: 6.5
EPSS: Критический
debian логотип

CVE-2023-2650

около 2 лет назад

Issue summary: Processing some specially crafted ASN.1 object identifi ...

CVSS3: 6.5
EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2471-1

около 2 лет назад

Security update for openssl1

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2469-1

около 2 лет назад

Security update for openssl

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2343-1

около 2 лет назад

Security update for openssl-1_1

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2342-1

около 2 лет назад

Security update for openssl-1_1

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2332-1

около 2 лет назад

Security update for openssl

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2331-1

около 2 лет назад

Security update for openssl-1_0_0

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2330-1

около 2 лет назад

Security update for openssl-1_0_0

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2329-1

около 2 лет назад

Security update for compat-openssl098

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2328-1

около 2 лет назад

Security update for openssl-1_1

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:2327-1

около 2 лет назад

Security update for openssl-1_1

EPSS: Критический
redos логотип

ROS-20230621-05

почти 2 года назад

Уязвимость Openssl

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-gqxg-9vfr-p9cg

около 2 лет назад

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time....

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:29171-1

почти 2 года назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2620-1

почти 2 года назад

Security update for openssl-3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-03652

Уязвимость библиотеки OpenSSL, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
92%
Критический
около 2 лет назад
ubuntu логотип
CVE-2023-2650

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time. The...

CVSS3: 6.5
92%
Критический
около 2 лет назад
redhat логотип
CVE-2023-2650

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time. T...

CVSS3: 6.5
92%
Критический
около 2 лет назад
nvd логотип
CVE-2023-2650

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time. T

CVSS3: 6.5
92%
Критический
около 2 лет назад
msrc логотип
CVSS3: 6.5
92%
Критический
около 2 лет назад
debian логотип
CVE-2023-2650

Issue summary: Processing some specially crafted ASN.1 object identifi ...

CVSS3: 6.5
92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2471-1

Security update for openssl1

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2469-1

Security update for openssl

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2343-1

Security update for openssl-1_1

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2342-1

Security update for openssl-1_1

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2332-1

Security update for openssl

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2331-1

Security update for openssl-1_0_0

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2330-1

Security update for openssl-1_0_0

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2329-1

Security update for compat-openssl098

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2328-1

Security update for openssl-1_1

92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2327-1

Security update for openssl-1_1

92%
Критический
около 2 лет назад
redos логотип
ROS-20230621-05

Уязвимость Openssl

CVSS3: 7.5
92%
Критический
почти 2 года назад
github логотип
GHSA-gqxg-9vfr-p9cg

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL type ASN1_OBJECT) to its canonical numeric text form, which are the sub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by periods. When one of the sub-identifiers in the OBJECT IDENTIFIER is very large (these are sizes that are seen as absurdly large, taking up tens or hundreds of KiBs), the translation to a decimal number in text may take a very long time....

CVSS3: 7.5
92%
Критический
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:29171-1

Security update for openssl-1_1

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:2620-1

Security update for openssl-3

почти 2 года назад

Уязвимостей на страницу