PT-2017-3765 · Openssl+8 · Openssl+8
David Benjamin
·
Publicado
2017-12-07
·
Atualizado
2024-06-15
·
CVE-2017-3737
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenSSL versions 1.0.2b through 1.0.2m
MySQL Server versions 5.6.38 and earlier
MySQL Server versions 5.7.20 and earlier
Description:
The issue is related to the incorrect handling of the "error state" mechanism in OpenSSL when
SSL read() or SSL write() functions are called directly. This can lead to the transmission of unencrypted confidential data over the network at the SSL/TLS level. The vulnerability can be exploited if an application bug results in a call to SSL read() or SSL write() after a fatal error has been received.Recommendations:
For OpenSSL versions 1.0.2b through 1.0.2m, update to OpenSSL 1.0.2n to resolve the issue.
For MySQL Server versions 5.6.38 and earlier, and 5.7.20 and earlier, consider restricting access to the affected MySQL Server component until a patch is available.
As a temporary workaround, consider disabling the use of
SSL read() and SSL write() functions directly in applications until the issue is resolved.Exploit
Correção
DoS
Memory Corruption
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Freebsd
Ibm Aix
Mysql Server
Openssl
Red Hat
Suse
Ubuntu