Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description The Open Source toolkit for Secure Sockets Layer and Transport Layer Security
Version 1.0.2.n-1 [core]


Group Affected Fixed Severity Status Ticket
AVG-550 1.0.2.l-2 1.0.2.n-1 Medium Fixed
AVG-479 1.0.2.l-1 1.0.2.n-1 Medium Fixed
Issue Group Severity Remote Type Description
CVE-2017-3738 AVG-550 Medium Yes Private key recovery
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected....
CVE-2017-3737 AVG-550 Medium Yes Information disclosure
OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then...
CVE-2017-3736 AVG-479 Medium Yes Information disclosure
A carry propagation bug has been found in OpenSSL < 1.1.0g in the x86_64 Montgomery squaring procedure. No EC algorithms are affected. Analysis suggests...
CVE-2017-3735 AVG-479 Low Yes Denial of service
A security issue has been found in OpenSSL < 1.1.0g. If an X.509 certificate has a malformed IPAddressFamily extension, OpenSSL could do a one-byte buffer...


Date Advisory Group Severity Description
16 Dec 2017 ASA-201712-9 AVG-479 Medium multiple issues