Lucene search

K
freebsdFreeBSDBAD6588E-2FE0-11EE-A0D1-84A93843EB75
HistoryJul 31, 2023 - 12:00 a.m.

OpenSSL -- Excessive time spent checking DH q parameter value

2023-07-3100:00:00
vuxml.freebsd.org
19
openssl
dh parameters
slow checks
unix

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.002 Low

EPSS

Percentile

56.4%

The OpenSSL project reports:

Checking excessively long DH keys or parameters may be very slow
(severity: Low).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchopenssl< 1.1.1u_1,1UNKNOWN
FreeBSDanynoarchopenssl30< 3.0.9_2UNKNOWN
FreeBSDanynoarchopenssl31< 3.1.1_2UNKNOWN

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.002 Low

EPSS

Percentile

56.4%