Lucene search

K
redosRedosROS-20230918-02
HistorySep 18, 2023 - 12:00 a.m.

ROS-20230918-02

2023-09-1800:00:00
redos.red-soft.ru
14
openssl
vulnerability
remote attackers
mm registers
windows 64 platform

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.8%

A vulnerability in the OpenSSL cryptographic library is related to insufficient validation of user input data in the POLY1305 MAC (message authentication code) implementation.
data in the POLY1305 MAC (message authentication code) implementation. Exploitation of the vulnerability could
allow an attacker acting remotely to send specially crafted input data to the application
and corrupt MM registers on a Windows 64 platform, resulting in a denial of service.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64openssl<ย 1.1.1q-8UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.8%