VulnerabilityModified
CVE-2017-3735
While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread.
MEDIUM 5.3EPSS 21.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 20.97% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- openssl/openssl · debian/debian linux
- Source
- openssl-security@openssl.org
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/100515Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039726Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3221
- https://access.redhat.com/errata/RHSA-2018:3505
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://github.com/openssl/openssl/commit/068b963bb7afc57f5bdd723de0dd15e7795d5822
- https://lists.debian.org/debian-lts-announce/2017/11/msg00011.html
- https://security.FreeBSD.org/advisories/FreeBSD-SA-17:11.openssl.asc
- https://security.gentoo.org/glsa/201712-03
- https://security.netapp.com/advisory/ntap-20170927-0001/Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171107-0002/Issue Tracking, Third Party Advisory
- https://support.apple.com/HT208331
- https://usn.ubuntu.com/3611-2/
- https://www.debian.org/security/2017/dsa-4017Third Party Advisory
- https://www.debian.org/security/2017/dsa-4018Third Party Advisory
- https://www.openssl.org/news/secadv/20170828.txtPatch, Vendor Advisory
- https://www.openssl.org/news/secadv/20171102.txtIssue Tracking, Vendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.tenable.com/security/tns-2017-14Issue Tracking, Third Party Advisory
- https://www.tenable.com/security/tns-2017-15
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.