PT-2013-1153 · Openssl+8 · Openssl+10

Karthikeyan Bhargavan

·

Publicado

2013-12-01

·

Atualizado

2024-06-15

·

CVE-2015-0205

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.0 through 1.0.0p OpenSSL versions 1.0.1 through 1.0.1k openssl-1.0.1e openssl-devel-1.0.1e openssl-static-1.0.1e openssl-libs-1.0.1e openssl-debuginfo-1.0.1e
Description The issue allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support. This is due to the ssl3 get cert verify function in s3 srvr.c in OpenSSL accepting client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message. The vulnerability can lead to disruption of protected information and can be exploited remotely.
Recommendations For OpenSSL versions 1.0.0 through 1.0.0p, update to version 1.0.0p or later. For OpenSSL versions 1.0.1 through 1.0.1k, update to version 1.0.1k or later. For openssl-1.0.1e, openssl-devel-1.0.1e, openssl-static-1.0.1e, openssl-libs-1.0.1e, and openssl-debuginfo-1.0.1e, update to a version that is not vulnerable. As a temporary workaround, consider disabling the ssl3 get cert verify function until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1023
BDU:2015-06127
BDU:2015-06128
BDU:2015-06129
BDU:2015-06130
BDU:2015-06131
BDU:2015-09142
BDU:2015-09143
BDU:2015-09144
BDU:2015-09145
BDU:2015-09146
BDU:2015-09819
BDU:2015-09905
CESA-2015_0066
CVE-2015-0205
DSA-3125-1
MGASA-2015-0022
OPENSUSE-SU-2015_0130-1
OPENSUSE-SU-2015_1277-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10309-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2015:0066
RHSA-2015_0066
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0305-1
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0547-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1183-2
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-403
USN-2459-1

Produtos afetados

Alt Linux
Centos
Cisco Ios
Cisco Ios Xe
Cisco Nexus
Ibm Aix
Junos
Openssl
Red Hat
Suse
Ubuntu