PT-2017-3765 · Openssl+8 · Openssl+8
David Benjamin
·
Published
2017-12-07
·
Updated
2024-06-15
·
CVE-2017-3737
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenSSL versions 1.0.2b through 1.0.2m
MySQL Server versions 5.6.38 and earlier
MySQL Server versions 5.7.20 and earlier
Description:
The issue is related to the incorrect handling of the "error state" mechanism in OpenSSL when
SSL read() or SSL write() functions are called directly. This can lead to the transmission of unencrypted confidential data over the network at the SSL/TLS level. The vulnerability can be exploited if an application bug results in a call to SSL read() or SSL write() after a fatal error has been received.Recommendations:
For OpenSSL versions 1.0.2b through 1.0.2m, update to OpenSSL 1.0.2n to resolve the issue.
For MySQL Server versions 5.6.38 and earlier, and 5.7.20 and earlier, consider restricting access to the affected MySQL Server component until a patch is available.
As a temporary workaround, consider disabling the use of
SSL read() and SSL write() functions directly in applications until the issue is resolved.Exploit
Fix
DoS
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Freebsd
Ibm Aix
Mysql Server
Openssl
Red Hat
Suse
Ubuntu