Lucene search

K
redosRedosROS-20240401-02
HistoryApr 01, 2024 - 12:00 a.m.

ROS-20240401-02

2024-04-0100:00:00
redos.red-soft.ru
8
openssl
dh_generate_key
vulnerability
remote
denial of service
unix

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

44.7%

A vulnerability in the DH_generate_key() function of the OpenSSL library is related to insufficient checking for unusual or
exceptional states. Exploitation of the vulnerability could allow a remote attacker,
cause a denial of service

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64openssl<= 1.1.1q-9UNKNOWN

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

44.7%