CVE-2017-3733Improper Input Validation in Openssl

Severity
7.5HIGHNVD
EPSS
3.1%
top 13.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateMay 14

Description

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/openssl< openssl 1.1.0e-1 (bookworm)
Debianopenssl/openssl< 1.1.0e-1+3
CVEListV5openssl/openssl5 versions+4
NVDopenssl/openssl5 versions+4
NVDhp/operations_agent11.14, 11.15+1

🔴Vulnerability Details

2
GHSA
GHSA-6553-6v42-5wqc: During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this2022-05-14
OSV
CVE-2017-3733: During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this2017-05-04

📋Vendor Advisories

7
Red Hat
openssl: Encrypt-Then-Mac renegotiation crash2017-02-16
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 20172017-01-31
Debian
CVE-2017-3733: openssl - During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated...2017
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017

💬Community

1
Bugzilla
CVE-2017-3733 openssl: Encrypt-Then-Mac renegotiation crash2017-02-13
CVE-2017-3733 — Improper Input Validation in Openssl | cvebase