CVE-2018-0739Uncontrolled Recursion in Openssl

Severity
6.5MEDIUMNVD
EPSS
14.4%
top 5.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMar 17

Description

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

debiandebian/openssl< libtomcrypt 1.18.2-1 (bookworm)
Debianopenssl/openssl< 1.1.0h-1+3
NVDopenssl/openssl1.0.2b1.0.2n+1
CVEListV5openssl/opensslFixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n), Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g)+1
debiandebian/libtomcrypt< libtomcrypt 1.18.2-1 (bookworm)

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2qcx-c97v-hcr6: Constructed ASN2022-05-13
OSV
CVE-2018-0739: Constructed ASN2018-03-27

📋Vendor Advisories

8
CISA ICS
CODESYS in Festo Automation Suite2026-03-17
CISA ICS
Festo Controller CECC-S,-LK,-D Family Firmware (Update A)2025-11-13
Oracle
Oracle Oracle Systems Risk Matrix: XCP Firmware (OpenSSL) — CVE-2018-07392021-07-15
Palo Alto
PAN-SA-2018-0015 OpenSSL Vulnerabilities in PAN-OS2018-10-12
Ubuntu
OpenSSL vulnerabilities2018-04-17

💬Community

3
Bugzilla
CVE-2018-0739 openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service2018-03-28
Bugzilla
CVE-2018-0739 mingw-openssl: openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service [epel-7]2018-03-28
Bugzilla
CVE-2018-0739 openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service [fedora-all]2018-03-28
CVE-2018-0739 — Uncontrolled Recursion in Openssl | cvebase