vulnerability
SUSE: CVE-2017-3731: SUSE Linux Security Advisory
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Jan 26, 2017 | Feb 10, 2017 | Feb 4, 2022 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Jan 26, 2017
Added
Feb 10, 2017
Modified
Feb 4, 2022
Description
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.
Solution(s)
suse-upgrade-libopenssl-1_0_0-develsuse-upgrade-libopenssl-1_1-develsuse-upgrade-libopenssl-1_1-devel-32bitsuse-upgrade-libopenssl-develsuse-upgrade-libopenssl1-develsuse-upgrade-libopenssl10suse-upgrade-libopenssl1_0_0suse-upgrade-libopenssl1_0_0-32bitsuse-upgrade-libopenssl1_0_0-hmacsuse-upgrade-libopenssl1_0_0-hmac-32bitsuse-upgrade-libopenssl1_0_0-x86suse-upgrade-libopenssl1_1suse-upgrade-libopenssl1_1-32bitsuse-upgrade-libopenssl1_1-hmacsuse-upgrade-libopenssl1_1-hmac-32bitsuse-upgrade-nodejs4suse-upgrade-nodejs4-develsuse-upgrade-nodejs4-docssuse-upgrade-nodejs6suse-upgrade-nodejs6-develsuse-upgrade-nodejs6-docssuse-upgrade-npm4suse-upgrade-npm6suse-upgrade-opensslsuse-upgrade-openssl-1_0_0suse-upgrade-openssl-1_0_0-docsuse-upgrade-openssl-1_1suse-upgrade-openssl-docsuse-upgrade-openssl1suse-upgrade-openssl1-docsuse-upgrade-sles12sp1-docker-imagesuse-upgrade-sles12sp2-docker-image
References
- SUSE-SUSE-SU-2017:0431-1
- SUSE-SUSE-SU-2017:0441-1
- SUSE-SUSE-SU-2017:0461-1
- SUSE-SUSE-SU-2017:0495-1
- SUSE-SUSE-SU-2017:0855-1
- SUSE-SUSE-SU-2017:2700-1
- SUSE-SUSE-SU-2017:2701-1
- SUSE-SUSE-SU-2018:0112-1
- REDHAT-RHSA-2017:0286
- REDHAT-RHSA-2018:2185
- REDHAT-RHSA-2018:2186
- REDHAT-RHSA-2018:2187
- DEBIAN-DLA-814-1
- DEBIAN-DSA-3773
- BID-95813
- SECTRACK-1037717
- FREEBSD-FreeBSD-SA-17:02
- GENTOO-GLSA-201702-07
- NVD-CVE-2017-3731
- UBUNTU-USN-3181-1

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.