CVE-2018-0739
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 18.60% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-674
- Affected
- openssl/openssl · canonical/ubuntu linux · debian/debian linux
- Source
- openssl-security@openssl.org
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/103518Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105609
- http://www.securitytracker.com/id/1040576Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3090
- https://access.redhat.com/errata/RHSA-2018:3221
- https://access.redhat.com/errata/RHSA-2018:3505
- https://access.redhat.com/errata/RHSA-2019:0366
- https://access.redhat.com/errata/RHSA-2019:0367
- https://access.redhat.com/errata/RHSA-2019:1711
- https://access.redhat.com/errata/RHSA-2019:1712
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2ac4c6f7b2b2af20c0e2b0ba05367e454cd11b33
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9310d45087ae546e27e61ddf8f6367f29848220d
- https://lists.debian.org/debian-lts-announce/2018/03/msg00033.htmlThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/
- https://security.gentoo.org/glsa/201811-21
- https://security.gentoo.org/glsa/202007-53
- https://security.netapp.com/advisory/ntap-20180330-0002/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180726-0002/
- https://securityadvisories.paloaltonetworks.com/Home/Detail/133
- https://usn.ubuntu.com/3611-1/Third Party Advisory
- https://usn.ubuntu.com/3611-2/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4157Third Party Advisory
- https://www.debian.org/security/2018/dsa-4158Third Party Advisory
- https://www.openssl.org/news/secadv/20180327.txtVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.