Buffer overflow in OpenSSL - CVE-2017-3738

 

Buffer overflow in OpenSSL - CVE-2017-3738

Published: December 8, 2017


Vulnerability identifier: #VU9595
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3738
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to buffer overflow in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. A remote attacker can cause the server to share the DH1024 private key among multiple clients and perform attack on TLS.

Affected software

OpenSSL
Debian Linux
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
FreeBSD
SUSE Linux
Slackware Linux
Ubuntu
nodejs-current (Alpine package)
Planning Analytics Local
MySQL Server

LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
WebSVN
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
NetWorker

How to mitigate CVE-2017-3738

Update to version 1.0.2n.

nodejs-current (Alpine package) - addressed in versions 7.2.1-r2, 7.10.1-r1
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
WebSVN - update to 1.61
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins