CVE-2017-3733
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
- Published date
- 2017-05-04T19:29Z
- Last modification date
- 2019-04-23T19:30Z
- Assigner
- openssl-security@openssl.org
- Problem type
- CWE-20
Impact
- CVSS v3 vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name | URL | Source | Tags |
---|---|---|---|
https://www.openssl.org/news/secadv/20170216.txt | https://www.openssl.org/news/secadv/20170216.txt | CONFIRM | Vendor Advisory |
96269 | http://www.securityfocus.com/bid/96269 | BID | Third Party Advisory, VDB Entry |
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03728en_us | https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03728en_us | CONFIRM | Third Party Advisory, VDB Entry |
1037846 | http://www.securitytracker.com/id/1037846 | SECTRACK | |
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | CONFIRM | |
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html | http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html | CONFIRM | |
https://github.com/openssl/openssl/commit/4ad93618d26a3ea23d36ad5498ff4f59eff3a4d2 | https://github.com/openssl/openssl/commit/4ad93618d26a3ea23d36ad5498ff4f59eff3a4d2 | MISC | |
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html | https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html | MISC |