The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
El analizador certificado en OpenSSL en versiones anteriores a 1.0.1u y 1.0.2 en versiones anteriores a 1.0.2i podría permitir a atacantes remotos provocar una denegación de servicio (lectura fuera de rango) a través de operaciones certificadas manipuladas, relacionado con s3_clnt.c y s3_srvr.c.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
AV:N/AC:M/Au:N/C:N/I:N/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-125
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| openssl | openssl | 1.0.1 | <built-in method update of dict object at 0x72a9ccd280c0> | Application |
| openssl | openssl | 1.0.1 | <built-in method update of dict object at 0x72a9ccd2ba40> | Application |
| openssl | openssl | 1.0.1 | <built-in method update of dict object at 0x72a9ccd29d00> | Application |
| openssl | openssl | 1.0.1 | <built-in method update of dict object at 0x72a9b0904240> | Application |
| openssl | openssl | 1.0.1a | <built-in method update of dict object at 0x72a9ccd28d00> | Application |
| openssl | openssl | 1.0.1b | <built-in method update of dict object at 0x72a9ccd2b200> | Application |
| openssl | openssl | 1.0.1c | <built-in method update of dict object at 0x72a9b0905b40> | Application |
| openssl | openssl | 1.0.1d | <built-in method update of dict object at 0x72a9b0904dc0> | Application |
| openssl | openssl | 1.0.1e | <built-in method update of dict object at 0x72a9ccd29100> | Application |
| openssl | openssl | 1.0.1f | <built-in method update of dict object at 0x72a9ccd2b280> | Application |
| openssl | openssl | 1.0.1g | <built-in method update of dict object at 0x72a9cdf31e00> | Application |
| openssl | openssl | 1.0.1h | <built-in method update of dict object at 0x72a9ccd2bf80> | Application |
| openssl | openssl | 1.0.1i | <built-in method update of dict object at 0x72a9ccd29c40> | Application |
| openssl | openssl | 1.0.1j | <built-in method update of dict object at 0x72a9b0b68200> | Application |
| openssl | openssl | 1.0.1k | <built-in method update of dict object at 0x72a9ccd28c40> | Application |
| openssl | openssl | 1.0.1l | <built-in method update of dict object at 0x72a9ccd2ac00> | Application |
| openssl | openssl | 1.0.1m | <built-in method update of dict object at 0x72a9ccd2bac0> | Application |
| openssl | openssl | 1.0.1n | <built-in method update of dict object at 0x72a9ccd29280> | Application |
| openssl | openssl | 1.0.1o | <built-in method update of dict object at 0x72a9b0906dc0> | Application |
| openssl | openssl | 1.0.1p | <built-in method update of dict object at 0x72a9b0904a00> | Application |
| openssl | openssl | 1.0.1q | <built-in method update of dict object at 0x72a9cc5dd580> | Application |
| openssl | openssl | 1.0.1r | <built-in method update of dict object at 0x72a9ccd2b780> | Application |
| openssl | openssl | 1.0.1s | <built-in method update of dict object at 0x72a9b0905480> | Application |
| openssl | openssl | 1.0.1t | <built-in method update of dict object at 0x72a9b0b68380> | Application |
| hp | icewall_federation_agent | 3.0 | <built-in method update of dict object at 0x72a9b0907ec0> | Application |
| hp | icewall_mcrp | 3.0 | <built-in method update of dict object at 0x72a9cc6d8100> | Application |
| hp | icewall_sso | 10.0 | <built-in method update of dict object at 0x72a9cc5de2c0> | Application |
| hp | icewall_sso | 10.0 | <built-in method update of dict object at 0x72a9b09057c0> | Application |
| hp | icewall_sso_agent_option | 10.0 | <built-in method update of dict object at 0x72a9b0b395c0> | Application |
| novell | suse_linux_enterprise_module_for_web_scripting | 12.0 | <built-in method update of dict object at 0x72a9b0b3afc0> | Operating System |
| openssl | openssl | 1.0.2 | <built-in method update of dict object at 0x72a9b0b3bdc0> | Application |
| openssl | openssl | 1.0.2 | <built-in method update of dict object at 0x72a9cd084100> | Application |
| openssl | openssl | 1.0.2 | <built-in method update of dict object at 0x72a9cd085ac0> | Application |
| openssl | openssl | 1.0.2 | <built-in method update of dict object at 0x72a9cd0865c0> | Application |
| openssl | openssl | 1.0.2a | <built-in method update of dict object at 0x72a9b0c65080> | Application |
| openssl | openssl | 1.0.2b | <built-in method update of dict object at 0x72a9b0c64280> | Application |
| openssl | openssl | 1.0.2c | <built-in method update of dict object at 0x72a9cd06f200> | Application |
| openssl | openssl | 1.0.2d | <built-in method update of dict object at 0x72a9b0c67280> | Application |
| openssl | openssl | 1.0.2e | <built-in method update of dict object at 0x72a9b0c672c0> | Application |
| openssl | openssl | 1.0.2f | <built-in method update of dict object at 0x72a9b0c65a00> | Application |
| openssl | openssl | 1.0.2h | <built-in method update of dict object at 0x72a9cd06dcc0> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9b0c65c80> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9b0c67a40> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9cd06ee00> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9b0c648c0> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9b0c64f80> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9b0c64100> | Application |
| debian | debian_linux | 8.0 | <built-in method update of dict object at 0x72a9cd06f7c0> | Operating System |
| canonical | ubuntu_linux | 12.04 | <built-in method update of dict object at 0x72a9b0c64e00> | Operating System |
| canonical | ubuntu_linux | 14.04 | <built-in method update of dict object at 0x72a9b0c67600> | Operating System |
| canonical | ubuntu_linux | 16.04 | <built-in method update of dict object at 0x72a9b0c675c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1s:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.1t:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:hp:icewall_federation_agent:3.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:hp:icewall_mcrp:3.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:hp:icewall_sso:10.0:*:*:*:certd:*:*:* |
| Yes | cpe:2.3:a:hp:icewall_sso:10.0:*:*:*:dfw:*:*:* |
| Yes | cpe:2.3:a:hp:icewall_sso_agent_option:10.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:novell:suse_linux_enterprise_module_for_web_scripting:12.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:openssl:openssl:1.0.2h:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* |
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* |
| Yes | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
| Yes | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |