Resource exhaustion in OpenSSL - CVE-2018-0739

 

Resource exhaustion in OpenSSL - CVE-2018-0739

Published: March 28, 2018 / Updated: May 1, 2018


Vulnerability identifier: #VU11294
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0739
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to excessive stack memory consumption. A remote attacker can cause the service to crash.

Affected software

OpenSSL
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
SUSE Linux
Slackware Linux
Opensuse
Fedora
nodejs-current (Alpine package)
compat-openssl10
openssl
libtomcrypt
IBM Cognos Business Intelligence Server
Cognos Insight
IBM Cognos Analytics
WebSVN
Flex System Chassis Management Module (CMM)
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
GCM16 & GCM32 KVM Switch Firmware
SBR Carrier
IBM Netezza Performance Server
NetWorker

How to mitigate CVE-2018-0739

Update to versions 1.1.0h or 1.0.2o.

nodejs-current (Alpine package) - addressed in versions 7.2.1-r2, 7.10.1-r1
IBM Cognos Analytics - update to 11.0.13
compat-openssl10 - addressed in versions 1.0.2o-1.fc26, 1.0.2o-1.fc27, 1.0.2o-1.fc28
openssl - addressed in versions 1.1.0h-1.fc26, 1.1.0h-1.fc27, 1.1.0h-2.fc28
libtomcrypt - addressed in versions 1.18.2-1.fc27, 1.18.2-1.fc28
WebSVN - update to 1.61
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
SBR Carrier - addressed in versions 8.4.1R13, 8.5.0R4
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.15.01.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.15.01.00
IBM Netezza Performance Server - update to 11.2.1.11
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins