VDB
BDU%3A2023-00665
BDU%3A2023-00665
PUBLISHED
CVSS 7.099999904632568 HIGH
Уязвимость функции GENERAL_NAME_cmp библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.099999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., ООО «РусБИТех-Астра», Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», АО «ИВК», OpenSSL Software Foundation, АО «НТЦ ИТ РОСА», Zimbra Inc., Hitachi, Ltd., Wazuh, Inc, АО "НППКТ", Oracle Corp., ООО «Открытая мобильная платформа», ООО «НЦПР» | Red Hat Enterprise Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, SUSE Linux Enterprise Software Development Kit, Jboss Web Server, JBoss Core Services, SUSE OpenStack Cloud, SUSE OpenStack Cloud Crowbar, SUSE CaaS Platform, SUSE Linux Enterprise High Performance Computing, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), OpenSUSE Leap, SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, Альт 8 СП (запись в едином реестре российских программ №4305), Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, openSUSE Leap Micro, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Module for Legacy Software, SUSE Linux Enterprise Real Time, OpenSSL, РОСА Кобальт (запись в едином реестре российских программ №1999), ROSA Virtualization (запись в едином реестре российских программ №5091), Zimbra Collaboration Suite, RTU500 series CMU, Red Hat JBoss Web Server, Wazuh, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), АЛЬТ СП 10, Oracle Exadata, ОС Аврора (запись в едином реестре российских программ №1543), ROSA Virtualization 3.0 (запись в едином реестре российских программ №21308), МСВСфера |
Timeline
- Feb 10, 2023 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://login.oracle.com/ url
- https://cve.omp.ru/bb25402 url
- https://security-tracker.debian.org/tracker/CVE-2023-0286 url
- https://access.redhat.com/security/cve/cve-2023-0286 url
- https://www.openssl.org/news/secadv/20230207.txt url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=2f7530077e0ef79d98718138716bc51ca0cad658 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9 url
- https://nvd.nist.gov/vuln/detail/CVE-2023-0286 url
- https://www.suse.com/security/cve/CVE-2023-0286.html url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2023-0303SE17MD url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2023-0316SE47MD url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-openssl-cve-2022-4304-cve-2022-4450-cve-2023-0286/?sphrase_id=163073 url
- https://abf.rosalinux.ru/advisories/ROSA-SA-2023-2152 url
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories url
- https://wiki.zimbra.com/wiki/Security_Center url
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-143-02 url
- https://library.e.abb.com/public/2a1f519e70474f7fabf8436b9cece25f/8DBD000150-VU-2023-004-OpenSSL_RTU500_Rev1.pdf?x-sign=0bg1XN9zG7lySsZ+ytx3v2Un6J8ZRZtlMjA1mJZE+u/GqrbJCrKiVnZ4hkI8HNuj url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.8/ url
- https://abf.rosalinux.ru/advisories/ROSA-SA-2023-2211 url
…and 6 more