Use-after-free error in pyopenssl - CVE-2018-1000807

 

Use-after-free error in pyopenssl - CVE-2018-1000807

Published: November 9, 2018


Vulnerability identifier: #VU15784
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000807
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.

The vulnerability exists due to use-after-free error during improper handling of X509 objects. A remote unauthenticated attacker can send a specially crafted request that submits malicious input, trigger memory corruption and cause the service to crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

pyopenssl
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
Opensuse
Red Hat OpenStack Director Deployment Tools
Red Hat OpenStack for IBM Power
Red Hat OpenStack
py-openssl (Alpine package)
python3-pyOpenSSL
python-pyOpenSSL

How to mitigate CVE-2018-1000807

Update to version 17.5.0.

pyopenssl - update to 17.5
py-openssl (Alpine package) - update to 17.5.0-r0
python3-pyOpenSSL - addressed in versions 17.1.0-4.26.1, 17.1.0-4.29.1
python-pyOpenSSL - addressed in versions 17.1.0-4.26.1, 17.1.0-4.29.1

External References

Related Security Bulletins