Improper input validation in OpenSSL - CVE-2018-0732
Published: June 12, 2018 / Updated: August 14, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to improper handling of large prime values by the affected software during key agreement operations in a Transport Layer Security (TLS) handshake using an Ephemeral Diffie-Hellman (DHE) based cipher suite. A remote attacker can send a large prime value from a malicious OpenSSL server to a targeted OpenSSL client and cause the client to stop responding while generating a key for the prime value.
Affected software
Gentoo Linux
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
openEuler
Fedora
Brocade Fabric OS
JD Edwards World Security
Oracle Enterprise Session Border Controller
Oracle Enterprise Communications Broker
Tivoli Network Manager IP Edition
Oracle Agile Engineering Data Management
Dynamic System Analysis (DSA) Preboot
Integrated Management Module II (IMM2) for BladeCenter Systems
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
Oracle Communications Unified Session Manager
Oracle Communications Session Border Controller
Oracle API Gateway
Oracle Enterprise Manager Ops Center
Orion Platform
openssl (Alpine package)
openssl (Debian package)
easy-rsa (Alpine package)
compat-openssl10
openssl
shim
shim-debuginfo
shim-debugsource
MySQL Enterprise Monitor
MySQL Server
IBM MQ
Oracle Endeca Server
Oracle Communications Diameter Signaling Router (DSR)
Primavera P6 Enterprise Project Portfolio Management
Enterprise Manager Base Platform
Oracle Communications WebRTC Session Controller
NetWorker
MySQL Workbench
Red Hat Openshift Application Runtimes
OSS Support Tools
PeopleSoft Enterprise PeopleTools
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
LCM8 & LCM16 KVM Switch Firmware
TIM 1531 IRC
GCM16 & GCM32 KVM Switch Firmware
Flex System Fabric CN4093 10Gb ScSE firmware
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
G8264CS_SI_Fabric_Image
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
SBR Carrier
How to mitigate CVE-2018-0732
openssl (Alpine package) - update to 1.0.2o-r1
openssl (Debian package) - update to 1.1.0j-1~deb9u1
easy-rsa (Alpine package) - update to 3.0.4-r1
MySQL Enterprise Monitor - addressed in versions 4.0.8, 8.0.14
IBM MQ - update to 5.3.1.15
MySQL Workbench - update to 8.0.14
Orion Platform - update to 2024.2
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
System x Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Flex System Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO86D-7.00-bc
compat-openssl10 - addressed in versions 1.0.2o-7.fc29, 1.0.2o-7.fc30, 1.0.2o-8.fc31
openssl - addressed in versions 1.1.0i-1.fc27, 1.1.0i-1.fc28
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
TIM 1531 IRC - update to 2.2
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
Oracle Communications WebRTC Session Controller - update to 7.2
Brocade Fabric OS - addressed in versions 7.4.2j, 8.2.0 CBN5, 8.2.3c
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.22.00
Flex System Fabric CN4093 10Gb ScSE firmware - update to 7.8.22.00
G8264CS_SI_Fabric_Image - update to 7.8.22.00
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.22.00
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.22.00
SBR Carrier - addressed in versions 8.4.1R13, 8.5.0R4
shim - update to 15-23
shim-debuginfo - update to 15-23
shim-debugsource - update to 15-23
OSS Support Tools - update to 19.1
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Denial of service in OpenSSL
- OpenSUSE Linux update for openssl
- OpenSUSE Linux update for openssl-1
- OpenSUSE Linux update for openssl-1
- Slackware Linux update for openssl
- Red Hat update for Node.js
- Red Hat update for Node.js
- OpenSUSE Linux update for nodejs4
- OpenSUSE Linux update for openssl-1
- OpenSUSE Linux update for openssl-1
- Amazon Linux AMI update for openssl
- Gentoo update for OpenSSL
- Multiple vulnerabilities in IBM MQ
- Debian update for openssl
- Debian update for openssl1.0
- Multiple vulnerabilities in Oracle MySQL
- Multiple vulnerabilities in Oracle Primavera
- OpenSUSE Linux update for nodejs8
- OpenSUSE Linux update for nodejs6
- OpenSUSE Linux update for compat-openssl098
- Red Hat update for openssl
- Improper input validation in openssl (Alpine package)
- Improper input validation in easy-rsa (Alpine package)
- Denial of service in Siemens TIM 1531 IRC
- Brocade Fabric OS update for OpenSSL
- Improper input validation in IBM Tivoli Network Manager IP Edition
- Juniper Networks Steel-Belted Radius (SBR) Carrier update for OpenSSL
- Multiple vulnerabilities in Dell Networker
- openEuler update for shim
- SolarWinds Platform update for third-party components
- Multiple vulnerabilities in IBM GCM16 & GCM32 and LCM8 & LCM16 KVM Switch Firmware
- Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot
- IBM Flex System switch firmware products update for OpenSSL
- IBM Integrated Management Module II (IMM2) update for OpenSSL
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Fedora 27 update for openssl
- Fedora 28 update for openssl
- Fedora 31 update for compat-openssl10
- Fedora 29 update for compat-openssl10
- Fedora 30 update for compat-openssl10
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router (DSR)
- Improper input validation in Oracle Agile Engineering Data Management
- Improper input validation in OSS Support Tools
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Improper input validation in MySQL Enterprise Monitor
- Multiple vulnerabilities in MySQL Workbench
- Improper input validation in JD Edwards World Security
- Improper input validation in Oracle API Gateway
- Improper input validation in Oracle Endeca Server
- Multiple vulnerabilities in Oracle Enterprise Manager Ops Center
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Improper input validation in Oracle Enterprise Session Border Controller
- Multiple vulnerabilities in Oracle Communications WebRTC Session Controller
- Improper input validation in Oracle Enterprise Communications Broker
- Multiple vulnerabilities in Oracle Communications Session Border Controller
- Improper input validation in Oracle Communications Unified Session Manager
- Multiple vulnerabilities in Primavera P6 Enterprise Project Portfolio Management