OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the public key of a certificate, as demonstrated by an RSA public key.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Hpux | — | Update fips_1_1_2.FIPS-RUN to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate fips_1_1_2.FIPS-LIB to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate fips_1_2.FIPS-SRC to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate fips_1_1_2.FIPS-CONF to the latest versionUpdate fips_1_1_2.FIPS-SRC to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate fips_1_1_2.FIPS-MIS to the latest versionUpdate fips_1_2.FIPS-DOC to the latest versionUpdate fips_1_2.FIPS-LIB to the latest versionUpdate fips_1_2.FIPS-INC to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate fips_1_2.FIPS-MAN to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate fips_1_2.FIPS-CONF to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate fips_1_1_2.FIPS-MAN to the latest versionUpdate fips_1_1_2.FIPS-DOC to the latest versionUpdate fips_1_1_2.FIPS-INC to the latest versionUpdate fips_1_2.FIPS-MIS to the latest versionUpdate fips_1_2.FIPS-RUN to the latest version | Aug 11, 2017 | Mar 27, 2009 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | May 29, 2009 | Mar 27, 2009 |
| Suse | — | Upgrade libopenssl1_1-hmacUpgrade libopenssl1-develUpgrade openssl1Upgrade libopenssl0_9_8-hmacUpgrade openssl-1_1Upgrade libopenssl1_1Upgrade libopenssl0_9_8-hmac-32bitUpgrade openssl-1_0_0-docUpgrade libopenssl0_9_8-x86Upgrade libopenssl-1_0_0-develUpgrade libopenssl-develUpgrade libopenssl0_9_8-32bitUpgrade libopenssl0_9_8Upgrade libopenssl1_0_0-hmacUpgrade libopenssl-1_1-devel-32bitUpgrade openssl-docUpgrade opensslUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl-fips-providerUpgrade libopenssl-1_1-develUpgrade libopenssl1_1-32bitUpgrade libopenssl1_0_0Upgrade openssl1-docUpgrade libopenssl1_0_0-hmac-32bitUpgrade openssl-1_0_0 | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub