Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Oct 1, 2024 | Mar 27, 2018 |
| Amazon_linux | — | Upgrade openssl | Aug 24, 2018 | Mar 27, 2018 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Mar 27, 2018 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Nov 29, 2018 | Mar 27, 2018 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 28, 2018 | Mar 27, 2018 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.2.15-0.175.3.32.0.1.0 on Solaris 11.3Upgrade library/security/openssl/openssl-fips-140 to version 2.0.12-0.175.3.32.0.1.0 on Solaris 11.3 | May 16, 2018 | Mar 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub