PT-2017-3765 · Openssl+8 · Openssl+8

David Benjamin

·

Publicado

2017-12-07

·

Atualizado

2024-06-15

·

CVE-2017-3737

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OpenSSL versions 1.0.2b through 1.0.2m MySQL Server versions 5.6.38 and earlier MySQL Server versions 5.7.20 and earlier
Description: The issue is related to the incorrect handling of the "error state" mechanism in OpenSSL when SSL read() or SSL write() functions are called directly. This can lead to the transmission of unencrypted confidential data over the network at the SSL/TLS level. The vulnerability can be exploited if an application bug results in a call to SSL read() or SSL write() after a fatal error has been received.
Recommendations: For OpenSSL versions 1.0.2b through 1.0.2m, update to OpenSSL 1.0.2n to resolve the issue. For MySQL Server versions 5.6.38 and earlier, and 5.7.20 and earlier, consider restricting access to the affected MySQL Server component until a patch is available. As a temporary workaround, consider disabling the use of SSL read() and SSL write() functions directly in applications until the issue is resolved.

Exploit

Correção

DoS

Memory Corruption

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2778
BDU:2019-00765
CESA-2018_0998
CVE-2017-3737
DSA-4065-1
FREEBSD-SA-17_12
MGASA-2017-0453
OPENSUSE-SU-2017_3345-1
OPENSUSE-SU-2018_0223-1
OPENSUSE-SU-2018_1057-1
OPENSUSE-SU-2024:11126-1
RHSA-2018:0998
RHSA-2018:2185
RHSA-2018:2186
RHSA-2018_0998
SUSE-FU-2022:0445-1
SUSE-SU-2017:3343-1
SUSE-SU-2017_3343-1
USN-3512-1

Produtos afetados

Alt Linux
Centos
Freebsd
Ibm Aix
Mysql Server
Openssl
Red Hat
Suse
Ubuntu