SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-3735

While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread.

MEDIUM 5.3EPSS 21.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 21.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
20.97% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
openssl/openssl · debian/debian linux
Source
openssl-security@openssl.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.