CVE-2010-1633Openssl vulnerability

CWE-2647 documents5 sources
Severity
6.4MEDIUMNVD
EPSS
0.8%
top 26.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 3
Latest updateMay 17

Description

RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x before 1.0.0a, as used by pkeyutl and possibly other applications, returns uninitialized memory upon failure, which might allow context-dependent attackers to bypass intended key requirements or obtain sensitive information via unspecified vectors. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

NVDopenssl/openssl1.0.0

Patches

🔴Vulnerability Details

1
GHSA
GHSA-4q7p-4wwf-p3r5: RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 12022-05-17

📋Vendor Advisories

2
Red Hat
openssl: information leak due to invalid Return value check2010-06-01
Debian
CVE-2010-1633: openssl - RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x...2010

💬Community

3
Bugzilla
CVE-2010-1633 openssl: information leak due to invalid Return value check2010-06-01
Bugzilla
CVE-2010-1633 openssl: information leak due to invalid Return value check [fedora-12]2010-06-01
Bugzilla
CVE-2010-1633 openssl: information leak due to invalid Return value check [fedora-13]2010-06-01