The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Hpux | — | Update fips_1_2.FIPS-RUN to the latest versionUpdate fips_1_1_2.FIPS-DOC to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate fips_1_1_2.FIPS-MAN to the latest versionUpdate fips_1_2.FIPS-MAN to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate fips_1_2.FIPS-CONF to the latest versionUpdate fips_1_2.FIPS-INC to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate fips_1_2.FIPS-MIS to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate fips_1_2.FIPS-SRC to the latest versionUpdate fips_1_1_2.FIPS-INC to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate fips_1_1_2.FIPS-RUN to the latest versionUpdate fips_1_1_2.FIPS-LIB to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate fips_1_1_2.FIPS-CONF to the latest versionUpdate fips_1_2.FIPS-DOC to the latest versionUpdate fips_1_2.FIPS-LIB to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate fips_1_1_2.FIPS-SRC to the latest versionUpdate fips_1_1_2.FIPS-MIS to the latest version | Aug 11, 2017 | Mar 27, 2009 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | May 29, 2009 | Mar 27, 2009 |
| Suse | — | Upgrade libopenssl1_0_0-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade openssl-1_1Upgrade libopenssl-1_1-devel-32bitUpgrade openssl-1_0_0Upgrade openssl1-docUpgrade libopenssl-1_0_0-develUpgrade libopenssl1_1Upgrade libopenssl1_0_0-hmacUpgrade openssl-docUpgrade opensslUpgrade libopenssl1_1-hmacUpgrade libopenssl0_9_8Upgrade libopenssl0_9_8-32bitUpgrade libopenssl0_9_8-hmac-32bitUpgrade openssl1Upgrade libopenssl1-develUpgrade libopenssl1_0_0Upgrade libopenssl0_9_8-hmacUpgrade openssl-1_0_0-docUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_1-32bitUpgrade libopenssl0_9_8-x86Upgrade libopenssl-develUpgrade libopenssl-fips-providerUpgrade libopenssl-1_1-devel | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub