PT-2017-3946 · Openssl+3 · Openssl+3

Published

2017-01-30

·

Updated

2019-04-23

·

CVE-2017-3733

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.1.0e
Description The issue is related to insufficient input validation in the Encrypt-Then-Mac extension of the OpenSSL library. This can be exploited by a remote attacker to cause a denial of service, resulting in a crash. The vulnerability is triggered during a renegotiation handshake when the Encrypt-Then-Mac extension is negotiated differently than in the original handshake. Both clients and servers are affected.
Recommendations For OpenSSL versions prior to 1.1.0e, update to version 1.1.0e or later to resolve the issue. As a temporary workaround, consider restricting the use of the Encrypt-Then-Mac extension during renegotiation handshakes until a patch is applied.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2639
BDU:2020-02911
CVE-2017-3733
MGASA-2017-0390

Affected Products

Alt Linux
Cisco Wls
Openssl
Virtualbox