Lucene search

K
ubuntuUbuntuUSN-6622-1
HistoryFeb 05, 2024 - 12:00 a.m.

OpenSSL vulnerabilities

2024-02-0500:00:00
ubuntu.com
41
openssl
ubuntu
vulnerabilities
denial of service
remote attack
pkcs12
rsa
powerpc architecture

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

6.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.3%

Releases

  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • openssl - Secure Socket Layer (SSL) cryptographic library and tools

Details

David Benjamin discovered that OpenSSL incorrectly handled excessively long
X9.42 DH keys. A remote attacker could possibly use this issue to cause
OpenSSL to consume resources, leading to a denial of service.
(CVE-2023-5678)

Sverker Eriksson discovered that OpenSSL incorrectly handled POLY1304 MAC
on the PowerPC architecture. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and
Ubuntu 23.04. (CVE-2023-6129)

It was discovered that OpenSSL incorrectly handled excessively long RSA
public keys. A remote attacker could possibly use this issue to cause
OpenSSL to consume resources, leading to a denial of service. This issue
only affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2023-6237)

Bahaa Naamneh discovered that OpenSSL incorrectly handled certain malformed
PKCS12 files. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2024-0727)

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchlibssl3< 3.0.10-1ubuntu2.2UNKNOWN
Ubuntu23.10noarchlibssl-dev< 3.0.10-1ubuntu2.2UNKNOWN
Ubuntu23.10noarchlibssl-doc< 3.0.10-1ubuntu2.2UNKNOWN
Ubuntu23.10noarchlibssl3-dbgsym< 3.0.10-1ubuntu2.2UNKNOWN
Ubuntu23.10noarchopenssl< 3.0.10-1ubuntu2.2UNKNOWN
Ubuntu23.10noarchopenssl-dbgsym< 3.0.10-1ubuntu2.2UNKNOWN
Ubuntu22.04noarchlibssl3< 3.0.2-0ubuntu1.14UNKNOWN
Ubuntu22.04noarchlibssl-dev< 3.0.2-0ubuntu1.14UNKNOWN
Ubuntu22.04noarchlibssl-doc< 3.0.2-0ubuntu1.14UNKNOWN
Ubuntu22.04noarchlibssl3-dbgsym< 3.0.2-0ubuntu1.14UNKNOWN
Rows per page:
1-10 of 201

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

6.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.3%