VDB
BDU%3A2023-02238
BDU%3A2023-02238
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функций EVP_DigestInit(), EVP_DigestUpdate() или EVP_DigestFinal() реализации стандарта PKCS #7 криптографической библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., ООО «Ред Софт», Canonical Ltd., Red Hat Inc., OpenSSL Software Foundation, Project Harbor | openSUSE Tumbleweed, РЕД ОС (запись в едином реестре российских программ №3751), OpenSUSE Leap, Suse Linux Enterprise Server, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, Ubuntu, Red Hat Enterprise Linux, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Basesystem, OpenSSL, harbor |
Timeline
- Apr 26, 2023 CVE Published
- Apr 16, 2024 CVE Updated
References
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-openssl-cve-2022-4304-cve-2022-4450-cve-2023-0286/?sphrase_id=163100 url
- https://access.redhat.com/security/cve/CVE-2023-0401 url
- https://www.openssl.org/news/secadv/20230207.txt url
- https://www.suse.com/security/cve/CVE-2023-0401.html url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=d3b6dfd70db844c4499bec6ad6601623a565e674 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://ubuntu.com/security/CVE-2023-0401 advisory