CVE-2017-3735Improper Restriction of Operations within the Bounds of a Memory Buffer in Software Foundation Openssl

Severity
5.3MEDIUMNVD
EPSS
36.9%
top 2.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 28
Latest updateMay 13

Description

While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

Debianopenssl/openssl< 1.1.0g-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.23+1
NVDopenssl/openssl88 versions+87
CVEListV5openssl_software_foundation/openssl1.0.2, 1.1.0+1

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-6h3q-hmhp-4vgv: While parsing an IPAddressFamily extension in an X2022-05-13
OSV
openssl vulnerabilities2017-11-06
OSV
CVE-2017-3735: While parsing an IPAddressFamily extension in an X2017-08-28
CVEList
CVE-2017-3735: While parsing an IPAddressFamily extension in an X2017-08-28

📋Vendor Advisories

6
Ubuntu
OpenSSL vulnerabilities2018-04-17
Apple
CVE-2017-3735: macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan2017-12-06
BSD
FreeBSD-SA-17:11.openssl: OpenSSL multiple vulnerabilities2017-11-29
Ubuntu
OpenSSL vulnerabilities2017-11-06
Red Hat
openssl: Malformed X.509 IPAdressFamily could cause OOB read2017-08-28

💬Community

4
Bugzilla
CVE-2017-3735 mingw-openssl: openssl: Malformed X.509 IPAdressFamily could cause OOB read [epel-7]2017-08-29
Bugzilla
CVE-2017-3735 openssl: Malformed X.509 IPAdressFamily could cause OOB read2017-08-29
Bugzilla
CVE-2017-3735 CVE-2017-3736 openssl: various flaws [fedora-all]2017-08-29
Bugzilla
CVE-2017-3735 CVE-2017-3736 mingw-openssl: various flaws [fedora-all]2017-08-29
CVE-2017-3735 — MEDIUM severity | cvebase