Use-after-free error in pyopenssl - CVE-2018-1000807
Published: November 9, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.
The vulnerability exists due to use-after-free error during improper handling of X509 objects. A remote unauthenticated attacker can send a specially crafted request that submits malicious input, trigger memory corruption and cause the service to crash or execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
Opensuse
Red Hat OpenStack Director Deployment Tools
Red Hat OpenStack for IBM Power
Red Hat OpenStack
py-openssl (Alpine package)
python3-pyOpenSSL
python-pyOpenSSL
How to mitigate CVE-2018-1000807
py-openssl (Alpine package) - update to 17.5.0-r0
python3-pyOpenSSL - addressed in versions 17.1.0-4.26.1, 17.1.0-4.29.1
python-pyOpenSSL - addressed in versions 17.1.0-4.26.1, 17.1.0-4.29.1