Resource exhaustion in pyopenssl - CVE-2018-1000808
Published: November 8, 2018 / Updated: November 9, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to improper release of memory before removing the last reference in a Public Key Cryptography Standards (PKCS) #12 store. A remote unauthenticated attacker can send a specially crafted request that submits malicious input, exhaust memory resources and to cause the application to reload certificates from a PKCS #12 store.
Affected software
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Red Hat OpenStack Director Deployment Tools
py-openssl (Alpine package)
python3-pyOpenSSL
python-pyOpenSSL
How to mitigate CVE-2018-1000808
py-openssl (Alpine package) - update to 17.5.0-r0
python3-pyOpenSSL - update to 17.1.0-4.26.1
python-pyOpenSSL - update to 17.1.0-4.26.1