PT-2018-2207 · Openssl+7 · Openssl+7

Publicado

2018-06-12

·

Atualizado

2024-06-15

·

CVE-2018-0732

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2 through 1.0.2o OpenSSL versions 1.1.0 through 1.1.0h
Description The issue is related to errors in cryptographic key processing when using the DH(E) protocol, which can be exploited by a remote attacker to cause a denial of service. During a TLS handshake using a DH(E) based ciphersuite, a malicious server can send a very large prime value to the client, causing the client to spend an unreasonably long period of time generating a key for this prime, resulting in a hang.
Recommendations For OpenSSL versions 1.0.2 through 1.0.2o, update to OpenSSL 1.0.2p-dev or later. For OpenSSL versions 1.1.0 through 1.1.0h, update to OpenSSL 1.1.0i-dev or later.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2232
ALT-PU-2018-2246
BDU:2019-00186
CESA-2018_3221
CVE-2018-0732
DLA-1449-1
DSA-4348-1
DSA-4355-1
MGASA-2018-0365
MGASA-2018-0437
OESA-2022-1938
OPENSUSE-SU-2018_1906-1
OPENSUSE-SU-2018_2117-1
OPENSUSE-SU-2018_2129-1
OPENSUSE-SU-2018_2667-1
OPENSUSE-SU-2018_2695-1
OPENSUSE-SU-2018_2816-1
OPENSUSE-SU-2018_2855-1
OPENSUSE-SU-2018_3013-1
OPENSUSE-SU-2018_3015-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
OPENSUSE-SU-2024:11501-1
RHSA-2018:2552
RHSA-2018:2553
RHSA-2018:3221
RHSA-2018_3221
RHSA-2019:1297
SUSE-FU-2022:0445-1
SUSE-SU-2018:1887-1
SUSE-SU-2018:1887-2
SUSE-SU-2018:1968-1
SUSE-SU-2018:2036-1
SUSE-SU-2018:2041-1
SUSE-SU-2018:2207-1
SUSE-SU-2018:2534-1
SUSE-SU-2018:2545-1
SUSE-SU-2018:2647-1
SUSE-SU-2018:2683-1
SUSE-SU-2018:2796-1
SUSE-SU-2018:2812-1
SUSE-SU-2018:2956-1
SUSE-SU-2018:2965-1
SUSE-SU-2018_1887-1
SUSE-SU-2018_1887-2
SUSE-SU-2018_1968-1
SUSE-SU-2018_2036-1
SUSE-SU-2018_2041-1
SUSE-SU-2018_2207-1
SUSE-SU-2018_2545-1
SUSE-SU-2018_2647-1
SUSE-SU-2018_2683-1
SUSE-SU-2018_2796-1
SUSE-SU-2018_2812-1
SUSE-SU-2018_2956-1
SUSE-SU-2018_2965-1
SUSE-SU-2019:14246-1
SUSE-SU-2019:1553-1
SUSE-SU-2019_14246-1
USN-3692-1
USN-3692-2

Produtos afetados

Alt Linux
Centos
Ibm Aix
Openssl
Red Hat
Suse
Ubuntu
Virtualbox