lib32-openssl-1.0

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description The Open Source toolkit for Secure Sockets Layer and Transport Layer Security
Version 1.0.2.u-1 [multilib]

Open

Group Affected Fixed Severity Status Ticket
AVG-2317 1.0.2.u-1 High Vulnerable
Issue Group Severity Remote Type Description
CVE-2021-23841 AVG-2317 Medium Yes Denial of service
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained...
CVE-2021-23840 AVG-2317 Low Yes Incorrect calculation
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to...
CVE-2021-23839 AVG-2317 Low Yes Incorrect calculation
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS...
CVE-2021-3712 AVG-2317 Medium Yes Information disclosure
A security issue has been found in OpenSSL before version 1.1.1l. ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which...
CVE-2021-3601 AVG-2317 Low Yes Insufficient validation
OpenSSL 1.0.2 will accept a certificate with explicitly set Basic Constraints to CA:FALSE as a valid CA if it is present in the trusted bundle.
CVE-2020-1971 AVG-2317 High Yes Denial of service
A denial of service security issue was discovered in OpenSSL before 1.1.1i. The X.509 GeneralName type is a generic type for representing different types of...
CVE-2020-1968 AVG-2317 Medium Yes Private key recovery
A flaw was found in openssl in versions 1.0.2 to 1.0.2w. A Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able...

Resolved

Group Affected Fixed Severity Status Ticket
AVG-918 1.0.2.q-1 1.0.2.r-1 Medium Fixed
AVG-806 1.0.2.p-1 1.0.2.q-1 Low Fixed
AVG-676 1.0.2.o-1 1.0.2.p-1 Low Fixed
AVG-480 1.0.2.l-2 1.0.2.n-1 Medium Fixed
Issue Group Severity Remote Type Description
CVE-2019-1559 AVG-918 Medium Yes Information disclosure
A padding oracle has been found in OpenSSL versions prior to 1.0.2r. This issue does not impact OpenSSL 1.1.1 or 1.1.0. If an application encounters a fatal...
CVE-2018-5407 AVG-806 Low No Private key recovery
A vulnerability has been found in the ECC scalar multiplication implementation of OpenSSL < 1.1.0i and <= 1.0.2p. The implementation, used in e.g. ECDSA and...
CVE-2018-0737 AVG-676 Low No Private key recovery
A cache-timing side channel attack in the RSA key generation algorithm has been found in OpenSSL <= 1.1.0h and <= 1.0.2o. An attacker with sufficient access...
CVE-2018-0734 AVG-806 Low Yes Private key recovery
A timing vulnerability has been found in DSA signature generation in openssl versions up to and including 1.1.1, where information is leaked via a side...
CVE-2018-0732 AVG-676 Low Yes Denial of service
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause...
CVE-2017-3738 AVG-480 Medium Yes Private key recovery
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected....
CVE-2017-3737 AVG-480 Medium Yes Information disclosure
OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then...
CVE-2017-3736 AVG-480 Medium Yes Information disclosure
A carry propagation bug has been found in OpenSSL < 1.1.0g in the x86_64 Montgomery squaring procedure. No EC algorithms are affected. Analysis suggests...
CVE-2017-3735 AVG-480 Low Yes Denial of service
A security issue has been found in OpenSSL < 1.1.0g. If an X.509 certificate has a malformed IPAddressFamily extension, OpenSSL could do a one-byte buffer...

Advisories

Date Advisory Group Severity Type
03 Mar 2019 ASA-201903-6 AVG-918 Medium information disclosure
08 Dec 2018 ASA-201812-7 AVG-806 Low private key recovery
17 Dec 2017 ASA-201712-11 AVG-480 Medium multiple issues