PT-2018-2207 · Openssl+7 · Openssl+7
Publicado
2018-06-12
·
Atualizado
2024-06-15
·
CVE-2018-0732
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.0.2 through 1.0.2o
OpenSSL versions 1.1.0 through 1.1.0h
Description
The issue is related to errors in cryptographic key processing when using the DH(E) protocol, which can be exploited by a remote attacker to cause a denial of service. During a TLS handshake using a DH(E) based ciphersuite, a malicious server can send a very large prime value to the client, causing the client to spend an unreasonably long period of time generating a key for this prime, resulting in a hang.
Recommendations
For OpenSSL versions 1.0.2 through 1.0.2o, update to OpenSSL 1.0.2p-dev or later.
For OpenSSL versions 1.1.0 through 1.1.0h, update to OpenSSL 1.1.0i-dev or later.
Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Ibm Aix
Openssl
Red Hat
Suse
Ubuntu
Virtualbox