crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | Feb 8, 2013 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Aug 28, 2015 | Feb 8, 2013 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Feb 8, 2013 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Feb 8, 2013 |
| Freebsd | — | Upgrade openssl | Dec 10, 2025 | Feb 6, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Feb 8, 2013 |
| Hpux | — | Update hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest version | Aug 11, 2017 | Feb 8, 2013 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 8, 2013 | Feb 8, 2013 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 1.2-0.175.1.7.0.4.0 on Solaris 11.1Upgrade library/security/openssl to version 1.0.0.11-0.175.1.7.0.4.0 on Solaris 11.1 | May 29, 2017 | Feb 8, 2013 |
| Suse | — | Upgrade libopenssl1_0_0-debuginfo-x86Upgrade libopenssl1_0_0-x86Upgrade opensslUpgrade libopenssl-devel-32bitUpgrade openssl-debuginfoUpgrade libopenssl1_0_0-debuginfoUpgrade openssl-debugsourceUpgrade libopenssl-develUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_0_0Upgrade openssl-docUpgrade libopenssl1_0_0-debuginfo-32bit | Dec 12, 2013 | Feb 8, 2013 |
| Ubuntu | — | Upgrade libssl0.9.8Upgrade libssl1.0.0 | Nov 8, 2024 | Feb 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub