Buffer overflow in OpenSSL - CVE-2017-3738
Published: December 8, 2017
Vulnerability identifier: #VU9595
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3738
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to buffer overflow in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. A remote attacker can cause the server to share the DH1024 private key among multiple clients and perform attack on TLS.
The weakness exists due to buffer overflow in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. A remote attacker can cause the server to share the DH1024 private key among multiple clients and perform attack on TLS.
Affected software
OpenSSL
Debian Linux
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
FreeBSD
SUSE Linux
Slackware Linux
Ubuntu
nodejs-current (Alpine package)
Planning Analytics Local
MySQL Server
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
WebSVN
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
NetWorker
Debian Linux
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
FreeBSD
SUSE Linux
Slackware Linux
Ubuntu
nodejs-current (Alpine package)
Planning Analytics Local
MySQL Server
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
WebSVN
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
NetWorker
How to mitigate CVE-2017-3738
Update to version 1.0.2n.
nodejs-current (Alpine package) - addressed in versions 7.2.1-r2, 7.10.1-r1
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
WebSVN - update to 1.61
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
NetWorker - update to 19.10.0.0
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
WebSVN - update to 1.61
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Slackware Linux update for openssl
- FreeBSD update for OpenSSL
- Ubuntu update for OpenSSL
- Gentoo update for OpenSSL
- Debian update for openssl1.0
- Arch Linux update for lib32-openssl-1.0
- Multiple vulnerabilities in Oracle MySQL Server
- Debian update for openssl
- Arch Linux update for openssl
- Red Hat update for openssl
- Arch Linux update for lib32-openssl
- Amazon Linux AMI update for openssl
- OpenSUSE Linux update for openssl
- SUSE Linux update for openssl
- Multiple vulnerabilities in IBM Planning Analytics Local
- Buffer overflow in nodejs-current (Alpine package)
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition
- Multiple vulnerabilities in QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module for IBM BladeCenter and QLogic Virtual Fabric Extension Module for IBM BladeCenter
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM GCM16 & GCM32 and LCM8 & LCM16 KVM Switch Firmware