PT-2018-1897 · Openssl+9 · Openssl+9

Published

2018-03-27

·

Updated

2024-06-15

·

CVE-2018-0739

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2b through 1.0.2n OpenSSL versions 1.1.0 through 1.1.0g MySQL Server versions 5.6.40 and earlier MySQL Server versions 5.7.22 and earlier MySQL Server versions 8.0.11 and earlier
Description The issue is related to constructed ASN.1 types with recursive definitions, which can cause a stack overflow when given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources, so this is considered safe in certain contexts. The vulnerability can be exploited by a remote attacker to cause a Denial of Service.
Recommendations For OpenSSL versions 1.0.2b through 1.0.2n, update to version 1.0.2o to resolve the issue. For OpenSSL versions 1.1.0 through 1.1.0g, update to version 1.1.0h to resolve the issue. For MySQL Server versions 5.6.40 and earlier, 5.7.22 and earlier, and 8.0.11 and earlier, update to a version later than the specified versions to resolve the issue. As a temporary workaround, consider restricting the use of recursive ASN.1 types to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1554
BDU:2018-01501
CESA-2018_3090
CESA-2018_3221
CVE-2018-0739
DLA-1330-1
DSA-4157-1
DSA-4158-1
MGASA-2018-0190
MGASA-2018-0257
MGASA-2018-0339
OPENSUSE-SU-2018_1057-1
OPENSUSE-SU-2018_2208-1
OPENSUSE-SU-2018_2238-1
OPENSUSE-SU-2018_2293-1
OPENSUSE-SU-2018_2524-1
OPENSUSE-SU-2018_2695-1
OPENSUSE-SU-2024:11003-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
OPENSUSE-SU-2024:11134-1
OPENSUSE-SU-2024:11501-1
RHSA-2018:3090
RHSA-2018:3221
RHSA-2018_3090
RHSA-2018_3221
RHSA-2019:0367
RHSA-2019:1711
SUSE-FU-2022:0445-1
SUSE-SU-2018:0902-1
SUSE-SU-2018:0905-1
SUSE-SU-2018:0906-1
SUSE-SU-2018:0925-1
SUSE-SU-2018:0975-1
SUSE-SU-2018:2072-1
SUSE-SU-2018:2158-1
SUSE-SU-2018:2534-1
SUSE-SU-2018:2683-1
SUSE-SU-2018_0902-1
SUSE-SU-2018_0905-1
SUSE-SU-2018_0906-1
SUSE-SU-2018_0925-1
SUSE-SU-2018_0975-1
SUSE-SU-2018_2072-1
SUSE-SU-2018_2158-1
SUSE-SU-2020:0495-1
SUSE-SU-2020_0495-1
USN-3611-1
USN-3611-2

Affected Products

Alt Linux
Centos
Huawei Vrp
Ibm Aix
Mysql Server
Openssl
Red Hat
Suse
Ubuntu
Virtualbox