PT-2018-9531 · Openssl+2 · Pyopenssl+2

Reaperhulk

·

Published

2018-10-08

·

Updated

2024-10-23

·

CVE-2018-1000807

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pyopenssl versions prior to 17.5.0
Description The issue is related to a Use After Free vulnerability in X509 object handling, which can result in denial of service or possible remote code execution. This attack appears to be exploitable via the calling application if it retains a reference to the memory.
Recommendations For versions prior to 17.5.0, update to version 17.5.0 or later to resolve the issue. As a temporary workaround, consider restricting the handling of X509 objects to minimize the risk of exploitation.

Fix

DoS

RCE

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2018-1000807
GHSA-P28M-34F6-967Q
OPENSUSE-SU-2019_1104-1
PYSEC-2018-23
RHSA-2019:0085
SUSE-RU-2019:1161-1
SUSE-SU-2018:4063-1
SUSE-SU-2018_4063-1
SUSE-SU-2024:1626-1
SUSE-SU-2024:3749-1
SUSE-SU-2024_1626-1
SUSE-SU-2024_3749-1
USN-3813-1

Affected Products

Suse
Ubuntu
Pyopenssl