CVE-2017-3733 REJECTED

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

EPSS 3.10% · 86.7th percentile

Risk Scores

EPSS Score
3.10%
86.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSopenssl0, 1.0.2d-0ubuntu1, 1.0.2d-0ubuntu2
Ubuntu:14.04:LTSopenssl1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.7, 1.0.1f-1ubuntu2.8

Timeline

References

Open in Interactive Console →