Improper input validation in OpenSSL - CVE-2018-0732

 

Improper input validation in OpenSSL - CVE-2018-0732

Published: June 12, 2018 / Updated: August 14, 2018


Vulnerability identifier: #VU13325
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0732
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to improper handling of large prime values by the affected software during key agreement operations in a Transport Layer Security (TLS) handshake using an Ephemeral Diffie-Hellman (DHE) based cipher suite. A remote attacker can send a large prime value from a malicious OpenSSL server to a targeted OpenSSL client and cause the client to stop responding while generating a key for the prime value.


Affected software

OpenSSL
Gentoo Linux
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Opensuse
openEuler
Fedora
Brocade Fabric OS
JD Edwards World Security
Oracle Enterprise Session Border Controller
Oracle Enterprise Communications Broker
Tivoli Network Manager IP Edition
Oracle Agile Engineering Data Management
Dynamic System Analysis (DSA) Preboot
Integrated Management Module II (IMM2) for BladeCenter Systems
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
Oracle Communications Unified Session Manager
Oracle Communications Session Border Controller
Oracle API Gateway
Oracle Enterprise Manager Ops Center
Orion Platform
openssl (Alpine package)
openssl (Debian package)
easy-rsa (Alpine package)
compat-openssl10
openssl
shim
shim-debuginfo
shim-debugsource
MySQL Enterprise Monitor
MySQL Server
IBM MQ
Oracle Endeca Server
Oracle Communications Diameter Signaling Router (DSR)
Primavera P6 Enterprise Project Portfolio Management
Enterprise Manager Base Platform
Oracle Communications WebRTC Session Controller
NetWorker
MySQL Workbench
Red Hat Openshift Application Runtimes
OSS Support Tools
PeopleSoft Enterprise PeopleTools
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
LCM8 & LCM16 KVM Switch Firmware
TIM 1531 IRC
GCM16 & GCM32 KVM Switch Firmware
Flex System Fabric CN4093 10Gb ScSE firmware
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
G8264CS_SI_Fabric_Image
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
SBR Carrier

How to mitigate CVE-2018-0732

Update to versions 1.1.0i or 1.0.2p.

OpenSSL - addressed in versions 1.0.2p, 1.1.0i
openssl (Alpine package) - update to 1.0.2o-r1
openssl (Debian package) - update to 1.1.0j-1~deb9u1
easy-rsa (Alpine package) - update to 3.0.4-r1
MySQL Enterprise Monitor - addressed in versions 4.0.8, 8.0.14
IBM MQ - update to 5.3.1.15
MySQL Workbench - update to 8.0.14
Orion Platform - update to 2024.2
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
System x Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Flex System Integrated Management Module (IMM2) - update to 1AOO86D-7.00
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO86D-7.00-bc
compat-openssl10 - addressed in versions 1.0.2o-7.fc29, 1.0.2o-7.fc30, 1.0.2o-8.fc31
openssl - addressed in versions 1.1.0i-1.fc27, 1.1.0i-1.fc28
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
Flex System Chassis Management Module (CMM) - update to 2pet16d-2.5.13d
TIM 1531 IRC - update to 2.2
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
Oracle Communications WebRTC Session Controller - update to 7.2
Brocade Fabric OS - addressed in versions 7.4.2j, 8.2.0 CBN5, 8.2.3c
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.22.00
Flex System Fabric CN4093 10Gb ScSE firmware - update to 7.8.22.00
G8264CS_SI_Fabric_Image - update to 7.8.22.00
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.22.00
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.22.00
SBR Carrier - addressed in versions 8.4.1R13, 8.5.0R4
shim - update to 15-23
shim-debuginfo - update to 15-23
shim-debugsource - update to 15-23
OSS Support Tools - update to 19.1
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins