PT-2013-1149 · Openssl+9 · Openssl+13

Publicado

2013-12-01

·

Atualizado

2026-03-10

·

CVE-2014-3570

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8zd OpenSSL versions prior to 1.0.0p OpenSSL versions prior to 1.0.1k
Description The BN sqr implementation in OpenSSL does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. Multiple vulnerabilities in the OpenSSL package may lead to a denial of service condition or allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerabilities can be exploited remotely.
Recommendations For versions prior to 0.9.8zd, update to version 0.9.8zd or later. For versions prior to 1.0.0p, update to version 1.0.0p or later. For versions prior to 1.0.1k, update to version 1.0.1k or later.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1023
ALT-PU-2015-2113
BDU:2015-06127
BDU:2015-06128
BDU:2015-06129
BDU:2015-06130
BDU:2015-06131
BDU:2015-09142
BDU:2015-09143
BDU:2015-09144
BDU:2015-09145
BDU:2015-09146
BDU:2015-09819
BDU:2015-09905
CESA-2015_0066
CVE-2014-3570
DLA-132-1
DSA-3125-1
HPSBUX03162
HPSBUX03244
MGASA-2015-0022
OPENSUSE-SU-2015_0130-1
OPENSUSE-SU-2015_1277-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10309-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2015:0066
RHSA-2015_0066
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0305-1
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0547-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1183-2
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-2015_0172-1
SUSE-SU-2015_0172-2
SUSE-SU-2015_0181-1
SUSE-SU-2015_0182-1
SUSE-SU-2015_0182-2
SUSE-SU-2015_0205-1
SUSE-SU-403
USN-2459-1

Produtos afetados

Alt Linux
Centos
Cisco Asa
Cisco Ios
Cisco Ios Xe
Cisco Nexus
Cisco Wls
Hp-Ux
Ibm Aix
Junos
Openssl
Red Hat
Suse
Ubuntu