PT-2008-6527 · Sun+1 · Sun Solaris+1

Publicado

2008-12-10

·

Atualizado

2017-09-29

·

CVE-2008-5410

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL PKCS#11 engine in Sun Solaris 10
Description The issue is related to the PK11 SESSION cache in the OpenSSL PKCS#11 engine, which does not maintain reference counts for operations with asymmetric keys. This allows attackers to cause a denial of service, resulting in failed cryptographic operations, via unspecified vectors. The problem is associated with the (1) RSA sign and (2) RSA verify functions.
Recommendations For Sun Solaris 10, consider disabling the use of asymmetric keys in the OpenSSL PKCS#11 engine as a temporary workaround until a patch is available. Restrict access to the RSA sign and RSA verify functions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5410

Produtos afetados

Openssl
Sun Solaris