CVE-2013-0166
published 2013-02-08CVE-2013-0166: OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
19.65%
97.1th percentile
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.0.1e-1 (bookworm) | openssl 1.0.1e-1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Chargeback Manager Remote Code Execution
vendor_vmware·2013-06-11·CVSS 5.0
CVE-2013-0166 [MEDIUM] VMware vCenter Chargeback Manager Remote Code Execution
VMSA-2013-0008: VMware vCenter Chargeback Manager Remote Code Execution
a. vCenter Chargeback Manager Remote Code Execution The vCenter Chargeback Manager (CBM) contains a flaw in its handling of file uploads. Exploitation of this issue may allow an unauthenticated attacker to execute code remotely. VMware would like to thank Andrea Micalizzi, aka rgod, for reporting this issue to us through HP's Zero Day Initiative (ZDI). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2013-3520 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with / Apply Patch VMware Product CBM Product Version 2.01 Running on an
BSD
FreeBSD-SA-13:03.openssl: OpenSSL multiple vulnerabilities
bsd_advisories·2013-04-02·CVSS 5.0
CVE-2013-0166 [MEDIUM] FreeBSD-SA-13:03.openssl: OpenSSL multiple vulnerabilities
FreeBSD-SA-13:03.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL multiple vulnerabilities
Category: contrib
Module: openssl
Announced: 2013-04-02
Affects: All supported versions of FreeBSD.
Corrected: 2013-03-08 17:28:40 UTC (stable/8, 8.3-STABLE)
2013-04-02 17:34:42 UTC (releng/8.3, 8.3-RELEASE-p7)
2013-03-14 17:48:07 UTC (stable/9, 9.1-STABLE)
2013-04-02 17:34:42 UTC (releng/9.0, 9.0-RELEASE-p7)
2013-04-02 17:34:42 UTC (releng/9.1, 9.1-RELEASE-p2)
CVE Name: CVE-2013-0166, CVE-2013-0169
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is
a collaborative effort to devel
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2013-02-21·CVSS 5.0
CVE-2012-2686 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Adam Langley and Wolfgang Ettlingers discovered that OpenSSL incorrectly
handled certain crafted CBC data when used with AES-NI. A remote attacker
could use this issue to cause OpenSSL to crash, resulting in a denial of
service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 12.10.
(CVE-2012-2686)
Stephen Henson discovered that OpenSSL incorrectly performed signature
verification for OCSP responses. A remote attacker could use this issue to
cause OpenSSL to crash, resulting in a denial of service. (CVE-2013-0166)
Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used
in OpenSSL was vulnerable to a timing side-channel attack known as the
"Lucky Thirteen" issue. A remote atta
Red Hat
openssl: DoS due to improper handling of OCSP response verification
vendor_redhat·2013-02-05·CVSS 5.0
CVE-2013-0166 [MEDIUM] openssl: DoS due to improper handling of OCSP response verification
openssl: DoS due to improper handling of OCSP response verification
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Package: openssl (Red Hat JBoss Enterprise Web Server 1) - Will not fix
Debian
CVE-2013-0166: openssl - OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not pro...
vendor_debian·2013·CVSS 5.0
CVE-2013-0166 [MEDIUM] CVE-2013-0166: openssl - OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not pro...
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
Scope: local
bookworm: resolved (fixed in 1.0.1e-1)
bullseye: resolved (fixed in 1.0.1e-1)
forky: resolved (fixed in 1.0.1e-1)
sid: resolved (fixed in 1.0.1e-1)
trixie: resolved (fixed in 1.0.1e-1)
GHSA
GHSA-f8qw-pqjg-gpv2: OpenSSL before 0
ghsa_unreviewed·2022-05-05
CVE-2013-0166 [MEDIUM] GHSA-f8qw-pqjg-gpv2: OpenSSL before 0
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
OSV
CVE-2013-0166: OpenSSL before 0
osv·2013-02-08·CVSS 5.0
CVE-2013-0166 [MEDIUM] CVE-2013-0166: OpenSSL before 0
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
No detection rules found.
No public exploits indexed.
http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=62e4506a7d4cec1c8e1ff687f6b220f6a62a57c7http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=66e8211c0b1347970096e04b18aa52567c325200http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=ebc71865f0506a293242bd4aec97cdc7a8ef24b0http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://marc.info/?l=bugtraq&m=136396549913849&w=2http://marc.info/?l=bugtraq&m=136432043316835&w=2http://marc.info/?l=bugtraq&m=137545771702053&w=2http://rhn.redhat.com/errata/RHSA-2013-0587.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0783.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0833.htmlhttp://secunia.com/advisories/53623http://secunia.com/advisories/55108http://secunia.com/advisories/55139http://support.apple.com/kb/HT5880http://www.debian.org/security/2013/dsa-2621http://www.kb.cert.org/vuls/id/737740http://www.openssl.org/news/secadv_20130204.txthttp://www.splunk.com/view/SP-CAAAHXGhttps://bugzilla.redhat.com/show_bug.cgi?id=908052https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18754https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19081https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19360https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19487https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=62e4506a7d4cec1c8e1ff687f6b220f6a62a57c7http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=66e8211c0b1347970096e04b18aa52567c325200http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=ebc71865f0506a293242bd4aec97cdc7a8ef24b0http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://marc.info/?l=bugtraq&m=136396549913849&w=2http://marc.info/?l=bugtraq&m=136432043316835&w=2http://marc.info/?l=bugtraq&m=137545771702053&w=2http://rhn.redhat.com/errata/RHSA-2013-0587.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0782.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0783.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0833.htmlhttp://secunia.com/advisories/53623http://secunia.com/advisories/55108http://secunia.com/advisories/55139http://support.apple.com/kb/HT5880http://www.debian.org/security/2013/dsa-2621http://www.kb.cert.org/vuls/id/737740http://www.openssl.org/news/secadv_20130204.txthttp://www.splunk.com/view/SP-CAAAHXGhttps://bugzilla.redhat.com/show_bug.cgi?id=908052https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18754https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19081https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19360https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19487https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001
2013-02-08
Published