PT-2012-1077 · Openssl+5 · Openssl+5

Published

2012-01-04

·

Updated

2024-06-15

·

CVE-2011-4108

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.0f OpenSSL versions prior to 1.0.0g OpenSSL version 1.0.0 OpenSSL-debuginfo version 1.0.0 OpenSSL-devel version 1.0.0 OpenSSL-static version 1.0.0
Description The issue affects the confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. The DTLS implementation in OpenSSL performs a MAC check only if certain padding is valid, making it easier for remote attackers to recover plaintext via a padding oracle attack. Additionally, the OpenSSL library implementation is vulnerable to a plain text recovery attack by performing timing analysis of the time required to decrypt encrypted data.
Recommendations For OpenSSL versions prior to 1.0.0f, update to version 1.0.0f or later. For OpenSSL versions prior to 1.0.0g, update to version 1.0.0g or later. For OpenSSL version 1.0.0, update to a newer version. For OpenSSL-debuginfo version 1.0.0, update to a newer version. For OpenSSL-devel version 1.0.0, update to a newer version. For OpenSSL-static version 1.0.0, update to a newer version. As a temporary workaround, consider restricting access to the DTLS implementation until a patch is available. Avoid using the DTLS implementation in the affected API endpoints until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06476
BDU:2015-06477
BDU:2015-06479
BDU:2015-06480
BDU:2015-08802
BDU:2015-08803
BDU:2015-08804
BDU:2015-08805
BDU:2015-09442
CESA-2012_0059
CVE-2011-4108
DSA-2390-1
HPSBUX02734
OPENSUSE-SU-2012_0083-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2012:0059
RHSA-2012:0060
RHSA-2012_0059
RHSA-2012_0060
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Affected Products

Centos
Hp-Ux
Ibm Aix
Openssl
Red Hat
Suse