Resource exhaustion in OpenSSL - CVE-2018-0739
Published: March 28, 2018 / Updated: May 1, 2018
Vulnerability identifier: #VU11294
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0739
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to excessive stack memory consumption. A remote attacker can cause the service to crash.
The weakness exists due to excessive stack memory consumption. A remote attacker can cause the service to crash.
Affected software
OpenSSL
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
SUSE Linux
Slackware Linux
Opensuse
Fedora
nodejs-current (Alpine package)
compat-openssl10
openssl
libtomcrypt
IBM Cognos Business Intelligence Server
Cognos Insight
IBM Cognos Analytics
WebSVN
Flex System Chassis Management Module (CMM)
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
GCM16 & GCM32 KVM Switch Firmware
SBR Carrier
IBM Netezza Performance Server
NetWorker
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
SUSE Linux
Slackware Linux
Opensuse
Fedora
nodejs-current (Alpine package)
compat-openssl10
openssl
libtomcrypt
IBM Cognos Business Intelligence Server
Cognos Insight
IBM Cognos Analytics
WebSVN
Flex System Chassis Management Module (CMM)
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
GCM16 & GCM32 KVM Switch Firmware
SBR Carrier
IBM Netezza Performance Server
NetWorker
How to mitigate CVE-2018-0739
Update to versions 1.1.0h or 1.0.2o.
nodejs-current (Alpine package) - addressed in versions 7.2.1-r2, 7.10.1-r1
IBM Cognos Analytics - update to 11.0.13
compat-openssl10 - addressed in versions 1.0.2o-1.fc26, 1.0.2o-1.fc27, 1.0.2o-1.fc28
openssl - addressed in versions 1.1.0h-1.fc26, 1.1.0h-1.fc27, 1.1.0h-2.fc28
libtomcrypt - addressed in versions 1.18.2-1.fc27, 1.18.2-1.fc28
WebSVN - update to 1.61
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
SBR Carrier - addressed in versions 8.4.1R13, 8.5.0R4
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.15.01.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.15.01.00
IBM Netezza Performance Server - update to 11.2.1.11
NetWorker - update to 19.10.0.0
IBM Cognos Analytics - update to 11.0.13
compat-openssl10 - addressed in versions 1.0.2o-1.fc26, 1.0.2o-1.fc27, 1.0.2o-1.fc28
openssl - addressed in versions 1.1.0h-1.fc26, 1.1.0h-1.fc27, 1.1.0h-2.fc28
libtomcrypt - addressed in versions 1.18.2-1.fc27, 1.18.2-1.fc28
WebSVN - update to 1.61
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
SBR Carrier - addressed in versions 8.4.1R13, 8.5.0R4
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.15.01.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.15.01.00
IBM Netezza Performance Server - update to 11.2.1.11
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Slackware Linux update for openssl
- Debian update for openssl
- Debian update for openssl1.0
- Arch Linux update for openssl
- SUSE Linux update for openssl
- SUSE Linux update for openssl
- SUSE Linux update for openssl1
- SUSE Linux update for openssl
- OpenSUSE Linux update for virtualbox
- Denial of service in IBM AIX
- Multiple vulnerabilities in IBM Cognos Insight
- Multiple vulnerabilities in IBM Cognos Business Intelligence Server
- OpenSUSE Linux update for ovmf
- OpenSUSE Linux update for ovmf
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in IBM Cognos Analytics
- Gentoo update for OpenSSL
- Amazon Linux AMI update for openssl
- OpenSUSE Linux update for compat-openssl098
- Red Hat update for ovmf
- Red Hat update for openssl
- Gentoo update for Dropbear
- Resource exhaustion in nodejs-current (Alpine package)
- Juniper Networks Steel-Belted Radius (SBR) Carrier update for OpenSSL
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM Netezza Performance Server
- Multiple vulnerabilities in IBM GCM16 & GCM32 KVM Switch Firmware
- Multiple vulnerabilities in IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Fedora 26 update for openssl
- Fedora 28 update for openssl
- Fedora 27 update for openssl
- Fedora 28 update for compat-openssl10
- Fedora 27 update for compat-openssl10
- Fedora 26 update for compat-openssl10
- Fedora 28 update for libtomcrypt
- Fedora 27 update for libtomcrypt