Количество 37
Количество 37
CVE-2022-2097
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
CVE-2022-2097
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
CVE-2022-2097
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
CVE-2022-2097
CVE-2022-2097
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimi ...
SUSE-SU-2022:2328-1
Security update for openssl-1_1
SUSE-SU-2022:2312-1
Security update for openssl-1_1
SUSE-SU-2022:2311-1
Security update for openssl-1_1
GHSA-3wx7-46ch-7rq2
AES OCB fails to encrypt some bytes
BDU:2022-04284
Уязвимость режима AES OCB библиотеки OpenSSL, позволяющая нарушителю раскрыть защищаемую информацию
SUSE-SU-2022:2309-1
Security update for openssl
SUSE-SU-2022:2308-1
Security update for openssl-1_1
RLSA-2022:5818
Moderate: openssl security update
ELSA-2022-9683
ELSA-2022-9683: openssl security update (MODERATE)
ELSA-2022-5818
ELSA-2022-5818: openssl security update (MODERATE)
ALT-PU-2023-7514
ALT-PU-2023-7514: package `mysql-connector-odbc` update to version 8.0.35-alt2
ALT-PU-2023-7323
ALT-PU-2023-7323: package `mysql-connector-odbc` update to version 8.0.35-alt1
ALT-PU-2022-2184
ALT-PU-2022-2184: package `openssl1.1` update to version 1.1.1q-alt1
ALT-PU-2022-2173
ALT-PU-2022-2173: package `openssl1.1` update to version 1.1.1q-alt1
SUSE-SU-2022:2417-1
Security update for nodejs12
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-2097 AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p). | CVSS3: 5.3 | 5% Низкий | около 4 лет назад | |
CVE-2022-2097 AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p). | CVSS3: 5.3 | 5% Низкий | около 4 лет назад | |
CVE-2022-2097 AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p). | CVSS3: 5.3 | 5% Низкий | около 4 лет назад | |
CVSS3: 5.3 | 5% Низкий | около 4 лет назад | ||
CVE-2022-2097 AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimi ... | CVSS3: 5.3 | 5% Низкий | около 4 лет назад | |
SUSE-SU-2022:2328-1 Security update for openssl-1_1 | 5% Низкий | около 4 лет назад | ||
SUSE-SU-2022:2312-1 Security update for openssl-1_1 | 5% Низкий | около 4 лет назад | ||
SUSE-SU-2022:2311-1 Security update for openssl-1_1 | 5% Низкий | около 4 лет назад | ||
GHSA-3wx7-46ch-7rq2 AES OCB fails to encrypt some bytes | CVSS3: 7.5 | 5% Низкий | около 4 лет назад | |
BDU:2022-04284 Уязвимость режима AES OCB библиотеки OpenSSL, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 3.7 | 5% Низкий | около 4 лет назад | |
SUSE-SU-2022:2309-1 Security update for openssl | около 4 лет назад | |||
SUSE-SU-2022:2308-1 Security update for openssl-1_1 | около 4 лет назад | |||
RLSA-2022:5818 Moderate: openssl security update | около 4 лет назад | |||
ELSA-2022-9683 ELSA-2022-9683: openssl security update (MODERATE) | около 4 лет назад | |||
ELSA-2022-5818 ELSA-2022-5818: openssl security update (MODERATE) | около 4 лет назад | |||
ALT-PU-2023-7514 ALT-PU-2023-7514: package `mysql-connector-odbc` update to version 8.0.35-alt2 | CVSS3: 9.1 | почти 3 года назад | ||
ALT-PU-2023-7323 ALT-PU-2023-7323: package `mysql-connector-odbc` update to version 8.0.35-alt1 | CVSS3: 9.1 | почти 3 года назад | ||
ALT-PU-2022-2184 ALT-PU-2022-2184: package `openssl1.1` update to version 1.1.1q-alt1 | CVSS3: 9.8 | около 4 лет назад | ||
ALT-PU-2022-2173 ALT-PU-2022-2173: package `openssl1.1` update to version 1.1.1q-alt1 | CVSS3: 9.8 | около 4 лет назад | ||
SUSE-SU-2022:2417-1 Security update for nodejs12 | около 4 лет назад |
Уязвимостей на страницу