PT-2012-1077 · Openssl+5 · Openssl+5

Publicado

2012-01-04

·

Atualizado

2024-06-15

·

CVE-2011-4108

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.0f OpenSSL versions prior to 1.0.0g OpenSSL version 1.0.0 OpenSSL-debuginfo version 1.0.0 OpenSSL-devel version 1.0.0 OpenSSL-static version 1.0.0
Description The issue affects the confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. The DTLS implementation in OpenSSL performs a MAC check only if certain padding is valid, making it easier for remote attackers to recover plaintext via a padding oracle attack. Additionally, the OpenSSL library implementation is vulnerable to a plain text recovery attack by performing timing analysis of the time required to decrypt encrypted data.
Recommendations For OpenSSL versions prior to 1.0.0f, update to version 1.0.0f or later. For OpenSSL versions prior to 1.0.0g, update to version 1.0.0g or later. For OpenSSL version 1.0.0, update to a newer version. For OpenSSL-debuginfo version 1.0.0, update to a newer version. For OpenSSL-devel version 1.0.0, update to a newer version. For OpenSSL-static version 1.0.0, update to a newer version. As a temporary workaround, consider restricting access to the DTLS implementation until a patch is available. Avoid using the DTLS implementation in the affected API endpoints until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06476
BDU:2015-06477
BDU:2015-06479
BDU:2015-06480
BDU:2015-08802
BDU:2015-08803
BDU:2015-08804
BDU:2015-08805
BDU:2015-09442
CESA-2012_0059
CVE-2011-4108
DSA-2390-1
HPSBUX02734
OPENSUSE-SU-2012_0083-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2012:0059
RHSA-2012:0060
RHSA-2012_0059
RHSA-2012_0060
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Produtos afetados

Centos
Hp-Ux
Ibm Aix
Openssl
Red Hat
Suse