VDB
BDU%3A2023-04957
BDU%3A2023-04957
PUBLISHED
CVSS 5 MEDIUM
Уязвимость функций DH_check(), DH_check_ex() или EVP_PKEY_param_check() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenSSL Software Foundation, ООО «РусБИТех-Астра», Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, Canonical Ltd., Oracle Corp., ООО «Ред Софт», АО «ИВК», АО «НТЦ ИТ РОСА», АО "НППКТ", Project Harbor, Node.js Foundation, Camunda Services GmbH | OpenSSL, Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, OpenSUSE Leap, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, Red Hat Enterprise Linux, SUSE Linux Enterprise Software Development Kit, SUSE Linux Enterprise Module for Legacy Software, Jboss Web Server, Debian GNU/Linux, JBoss Core Services, openSUSE Tumbleweed, Ubuntu, SUSE CaaS Platform, Oracle Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, SUSE Linux Enterprise Micro, Альт 8 СП (запись в едином реестре российских программ №4305), Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, SUSE Linux Enterprise Module for Basesystem, openSUSE Leap Micro, SUSE Linux Enterprise Real Time, ROSA Virtualization (запись в едином реестре российских программ №5091), РОСА ХРОМ (запись в едином реестре российских программ №1607), АЛЬТ СП 10, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), SUSE Liberty Linux, harbor, Node.js, Camunda Modeler |
Timeline
- Aug 29, 2023 CVE Published
- Mar 19, 2025 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- http://www.openwall.com/lists/oss-security/2023/07/19/4 url
- http://www.openwall.com/lists/oss-security/2023/07/19/5 url
- http://www.openwall.com/lists/oss-security/2023/07/19/6 url
- http://www.openwall.com/lists/oss-security/2023/07/31/1 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528 url
- https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html url
- https://security.netapp.com/advisory/ntap-20230803-0011/ url
- https://www.openssl.org/news/secadv/20230719.txt url
- https://vuldb.com/ru/?id.235010 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.9/ url
- https://ubuntu.com/security/notices/USN-6435-2 url
- https://ubuntu.com/security/notices/USN-6450-1 url
- https://ubuntu.com/security/notices/USN-6435-1 url
- https://security-tracker.debian.org/tracker/CVE-2023-3446 url
- https://linux.oracle.com/cve/CVE-2023-3446.html url
- https://abf.rosalinux.ru/advisories/ROSA-SA-2024-2366 url
- https://cve.basealt.ru/report-19102023-c10f1-c9f2.html url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-openssl-cve-2023-3446-cve-2023-3817/?sphrase_id=370415 url
…and 9 more