crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | Feb 8, 2013 |
| Apple Osx Apache | — | Apply OS X security update 2013-004Upgrade macOS to the latest version | Aug 28, 2015 | Feb 8, 2013 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Feb 8, 2013 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Feb 8, 2013 |
| Freebsd | — | Upgrade openssl | Dec 10, 2025 | Feb 6, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Feb 8, 2013 |
| Hpux | — | Update hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest version | Aug 11, 2017 | Feb 8, 2013 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 8, 2013 | Feb 8, 2013 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 1.2-0.175.1.7.0.4.0 on Solaris 11.1Upgrade library/security/openssl to version 1.0.0.11-0.175.1.7.0.4.0 on Solaris 11.1 | May 29, 2017 | Feb 8, 2013 |
| Suse | — | Upgrade libopenssl1_1-hmac-32bitUpgrade openssl1Upgrade libopenssl1_1-hmacUpgrade libopenssl1_1Upgrade libopenssl1-develUpgrade openssl-1_1Upgrade openssl-1_0_0-docUpgrade opensslUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_0_0-hmacUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_1-32bitUpgrade openssl-docUpgrade libopenssl-develUpgrade libopenssl1_0_0Upgrade libopenssl-fips-providerUpgrade openssl-1_0_0Upgrade libopenssl-1_0_0-develUpgrade openssl1-docUpgrade libopenssl-1_1-devel | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libssl0.9.8Upgrade libssl1.0.0 | Nov 8, 2024 | Feb 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub