PT-2017-3765 · Openssl+8 · Openssl+8

David Benjamin

·

Published

2017-12-07

·

Updated

2024-06-15

·

CVE-2017-3737

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OpenSSL versions 1.0.2b through 1.0.2m MySQL Server versions 5.6.38 and earlier MySQL Server versions 5.7.20 and earlier
Description: The issue is related to the incorrect handling of the "error state" mechanism in OpenSSL when SSL read() or SSL write() functions are called directly. This can lead to the transmission of unencrypted confidential data over the network at the SSL/TLS level. The vulnerability can be exploited if an application bug results in a call to SSL read() or SSL write() after a fatal error has been received.
Recommendations: For OpenSSL versions 1.0.2b through 1.0.2m, update to OpenSSL 1.0.2n to resolve the issue. For MySQL Server versions 5.6.38 and earlier, and 5.7.20 and earlier, consider restricting access to the affected MySQL Server component until a patch is available. As a temporary workaround, consider disabling the use of SSL read() and SSL write() functions directly in applications until the issue is resolved.

Exploit

Fix

DoS

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2778
BDU:2019-00765
CESA-2018_0998
CVE-2017-3737
DSA-4065-1
FREEBSD-SA-17_12
MGASA-2017-0453
OPENSUSE-SU-2017_3345-1
OPENSUSE-SU-2018_0223-1
OPENSUSE-SU-2018_1057-1
OPENSUSE-SU-2024:11126-1
RHSA-2018:0998
RHSA-2018:2185
RHSA-2018:2186
RHSA-2018_0998
SUSE-FU-2022:0445-1
SUSE-SU-2017:3343-1
SUSE-SU-2017_3343-1
USN-3512-1

Affected Products

Alt Linux
Centos
Freebsd
Ibm Aix
Mysql Server
Openssl
Red Hat
Suse
Ubuntu