VDB
BDU%3A2023-04959
BDU%3A2023-04959
PUBLISHED
CVSS 5 MEDIUM
Уязвимость алгоритма шифрования AES-SIV библиотеки OpenSSL, позволяющая нарушителю обойти процесс аутентификации
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Canonical Ltd., OpenSSL Software Foundation, Project Harbor, Node.js Foundation, Camunda Services GmbH | OpenSUSE Leap, Debian GNU/Linux, openSUSE Tumbleweed, РЕД ОС (запись в едином реестре российских программ №3751), Suse Linux Enterprise Server, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, Ubuntu, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Basesystem, OpenSSL, harbor, Node.js, Camunda Modeler |
Timeline
- Aug 29, 2023 CVE Published
- Apr 15, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- http://www.openwall.com/lists/oss-security/2023/07/15/1 url
- http://www.openwall.com/lists/oss-security/2023/07/19/5 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=6a83f0c958811f07e0d11dfc6b5a6a98edfd5bdc url
- https://security.netapp.com/advisory/ntap-20230725-0004/ url
- https://www.openssl.org/news/secadv/20230714.txt url
- https://vuldb.com/ru/?id.234166 url
- https://www.cybersecurity-help.cz/vdb/SB2023071506 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=00e2f5eea29994d19293ec4e8c8775ba73678598 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://security-tracker.debian.org/tracker/CVE-2023-2975 advisory
- https://www.suse.com/security/cve/CVE-2023-2975.html advisory
- https://ubuntu.com/security/notices/USN-6450-1 advisory
- https://ubuntu.com/security/CVE-2023-2975 advisory