Lucene search

K
f5F5F5:K37526132
HistoryFeb 23, 2017 - 12:00 a.m.

K37526132 : OpenSSL vulnerability CVE-2017-3731

2017-02-2300:00:00
my.f5.com
51

AI Score

7.7

Confidence

High

EPSS

0.046

Percentile

92.5%

Security Advisory Description

If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k. (CVE-2017-3731)
Impact
A truncated packet may cause a server or client to perform an out-of-bounds read, possibly resulting in the system becoming unresponsive.