Vulnerabilidad en OpenSSL (CVE-2017-3731)
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-125
Lectura fuera de límites
Fecha de publicación:
04/05/2017
Última modificación:
20/04/2025
Descripción
Si un servidor o cliente SSL/TLS se ejecuta en un host de 32 bits y se utiliza un cifrador específico, un paquete truncado puede dar lugar a que el servidor o el cliente realicen una lectura fuera de límites que, normalmente, provoca un cierre inesperado En OpenSSL 1.1.0, el cierre inesperado se puede desencadenar cuando se usa CHACHA20/POLY1305
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Puntuación base 2.0
5.00
Gravedad 2.0
MEDIA
Productos y versiones vulnerables
CPE | Desde | Hasta |
---|---|---|
cpe:2.3:a:openssl:openssl:1.1.0a:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.1.0b:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.1.0c:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2h:*:*:*:*:*:*:* | ||
cpe:2.3:a:openssl:openssl:1.0.2i:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://rhn.redhat.com/errata/RHSA-2017-0286.html
- http://www.debian.org/security/2017/dsa-3773
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/95813
- http://www.securitytracker.com/id/1037717
- https://access.redhat.com/errata/RHSA-2018:2185
- https://access.redhat.com/errata/RHSA-2018:2186
- https://access.redhat.com/errata/RHSA-2018:2187
- https://github.com/openssl/openssl/commit/00d965474b22b54e4275232bc71ee0c699c5cd21
- https://security.FreeBSD.org/advisories/FreeBSD-SA-17:02.openssl.asc
- https://security.gentoo.org/glsa/201702-07
- https://security.netapp.com/advisory/ntap-20171019-0002/
- https://security.paloaltonetworks.com/CVE-2017-3731
- https://source.android.com/security/bulletin/pixel/2017-11-01
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03838en_us
- https://www.openssl.org/news/secadv/20170126.txt
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.tenable.com/security/tns-2017-04
- http://rhn.redhat.com/errata/RHSA-2017-0286.html
- http://www.debian.org/security/2017/dsa-3773
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/bid/95813
- http://www.securitytracker.com/id/1037717
- https://access.redhat.com/errata/RHSA-2018:2185
- https://access.redhat.com/errata/RHSA-2018:2186
- https://access.redhat.com/errata/RHSA-2018:2187
- https://github.com/openssl/openssl/commit/00d965474b22b54e4275232bc71ee0c699c5cd21
- https://security.FreeBSD.org/advisories/FreeBSD-SA-17:02.openssl.asc
- https://security.gentoo.org/glsa/201702-07
- https://security.netapp.com/advisory/ntap-20171019-0002/
- https://security.paloaltonetworks.com/CVE-2017-3731
- https://source.android.com/security/bulletin/pixel/2017-11-01
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03838en_us
- https://www.openssl.org/news/secadv/20170126.txt
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.tenable.com/security/tns-2017-04