CVE-2018-1000807
published 2018-10-08CVE-2018-1000807: Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can…
PriorityP345high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
4.08%
89.6th percentile
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | pyopenssl | < pyopenssl 17.5.0-1 (bookworm) | pyopenssl 17.5.0-1 (bookworm) |
| pyopenssl | pyopenssl | < 17.5.0 | 17.5.0 |
| pyopenssl | pyopenssl | >= 0 < 17.5.0-1 | 17.5.0-1 |
| pyopenssl | pyopenssl | >= 0 < 17.5.0-1 | 17.5.0-1 |
| pyopenssl | pyopenssl | >= 0 < 17.5.0-1 | 17.5.0-1 |
| pyopenssl | pyopenssl | >= 0 < 17.5.0-1 | 17.5.0-1 |
| pyopenssl | pyopenssl | >= 0 < 17.5.0 | 17.5.0 |
| pyopenssl | pyopenssl | >= 0 < 0.15.1-2ubuntu0.2 | 0.15.1-2ubuntu0.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
pyOpenSSL vulnerabilities
vendor_ubuntu·2018-11-08·CVSS 8.1
CVE-2018-1000807 [HIGH] pyOpenSSL vulnerabilities
Title: pyOpenSSL vulnerabilities
Summary: Several security issues were fixed in pyOpenSSL.
It was discovered that pyOpenSSL incorrectly handled memory when handling
X509 objects. A remote attacker could use this issue to cause pyOpenSSL to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2018-1000807)
It was discovered that pyOpenSSL incorrectly handled memory when performing
operations on a PKCS #12 store. A remote attacker could possibly use this
issue to cause pyOpenSSL to consume resources, resulting in a denial of
service. (CVE-2018-1000808)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-1000807: pyopenssl - Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contain...
vendor_debian·2018·CVSS 8.1
CVE-2018-1000807 [HIGH] CVE-2018-1000807: pyopenssl - Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contain...
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.
Scope: local
bookworm: resolved (fixed in 17.5.0-1)
bullseye: resolved (fixed in 17.5.0-1)
forky: resolved (fixed in 17.5.0-1)
sid: resolved (fixed in 17.5.0-1)
trixie: resolved (fixed in 17.5.0-1)
Red Hat
pyOpenSSL: Use-after-free in X509 object handling
vendor_redhat·2017-11-29·CVSS 8.1
CVE-2018-1000807 [HIGH] CWE-416 pyOpenSSL: Use-after-free in X509 object handling
pyOpenSSL: Use-after-free in X509 object handling
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.
Statement: This vulnerability is only present when a specific and uncommon usage pattern of pyOpenSSL occurs. Red Hat Product Security has audited our packages that use pyOpenSSL, and determined that software we distribute in Red Hat Enterprise Linux and Red Hat Virtualization does not use pyOpenSSL in such a way as to be
OSV
pyopenssl vulnerabilities
osv·2018-11-08·CVSS 8.1
CVE-2018-1000807 [HIGH] pyopenssl vulnerabilities
pyopenssl vulnerabilities
It was discovered that pyOpenSSL incorrectly handled memory when handling
X509 objects. A remote attacker could use this issue to cause pyOpenSSL to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2018-1000807)
It was discovered that pyOpenSSL incorrectly handled memory when performing
operations on a PKCS #12 store. A remote attacker could possibly use this
issue to cause pyOpenSSL to consume resources, resulting in a denial of
service. (CVE-2018-1000808)
GHSA
PyOpenSSL Use-After-Free vulnerability
ghsa·2018-10-10
CVE-2018-1000807 [HIGH] CWE-416 PyOpenSSL Use-After-Free vulnerability
PyOpenSSL Use-After-Free vulnerability
It was discovered that pyOpenSSL incorrectly handled memory when handling X509 objects. A remote attacker could use this issue to cause pyOpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code. This attack appears to be exploitable via Depends on the calling application and if it retains a reference to the memory. This vulnerability appears to have been fixed in 17.5.0.
OSV
PyOpenSSL Use-After-Free vulnerability
osv·2018-10-10
CVE-2018-1000807 [HIGH] PyOpenSSL Use-After-Free vulnerability
PyOpenSSL Use-After-Free vulnerability
It was discovered that pyOpenSSL incorrectly handled memory when handling X509 objects. A remote attacker could use this issue to cause pyOpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code. This attack appears to be exploitable via Depends on the calling application and if it retains a reference to the memory. This vulnerability appears to have been fixed in 17.5.0.
OSV
CVE-2018-1000807: Python Cryptographic Authority pyopenssl version prior to version 17
osv·2018-10-08·CVSS 8.1
CVE-2018-1000807 [HIGH] CVE-2018-1000807: Python Cryptographic Authority pyopenssl version prior to version 17
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000807 CVE-2018-1000808 pyOpenSSL: various flaws [fedora-28]
bugzilla·2018-10-17·CVSS 8.1
CVE-2018-1000807 [HIGH] CVE-2018-1000807 CVE-2018-1000808 pyOpenSSL: various flaws [fedora-28]
CVE-2018-1000807 CVE-2018-1000808 pyOpenSSL: various flaws [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg u
Bugzilla
CVE-2018-1000807 pyOpenSSL: Use-after-free in X509 object handling
bugzilla·2018-10-17·CVSS 8.1
CVE-2018-1000807 [HIGH] CVE-2018-1000807 pyOpenSSL: Use-after-free in X509 object handling
CVE-2018-1000807 pyOpenSSL: Use-after-free in X509 object handling
Python Cryptographic Authority pyopenssl version before 17.5.0 has a use-after-free vulnerability in X509 object handling. This can result in a denial of service or potentially even code execution
Upstream issue:
https://github.com/pyca/pyopenssl/pull/723
Discussion:
Created pyOpenSSL tracking bugs for this issue:
Affects: fedora-28 [bug 1640218]
Affects: openstack-rdo [bug 1640219]
---
Based on discussions with engineering, and examination of the code we ship that uses pyOpenSSL, the severity of this issue has been downgraded. This vulnerability is only exposed when a verify callback stores a reference to the x509 object that will outlive the connection, which is a very unusual need for most applications. We have n
Bugzilla
CVE-2018-1000807 CVE-2018-1000808 pyOpenSSL: various flaws [openstack-rdo]
bugzilla·2018-10-17·CVSS 8.1
CVE-2018-1000807 [HIGH] CVE-2018-1000807 CVE-2018-1000808 pyOpenSSL: various flaws [openstack-rdo]
CVE-2018-1000807 CVE-2018-1000808 pyOpenSSL: various flaws [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
This CVE was fixed in pyOpenSSL-17.5.0.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00014.htmlhttps://access.redhat.com/errata/RHSA-2019:0085https://github.com/pyca/pyopenssl/commit/e73818600065821d588af475b024f4eb518c3509https://github.com/pyca/pyopenssl/pull/723https://usn.ubuntu.com/3813-1/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00014.htmlhttps://access.redhat.com/errata/RHSA-2019:0085https://github.com/pyca/pyopenssl/commit/e73818600065821d588af475b024f4eb518c3509https://github.com/pyca/pyopenssl/pull/723https://usn.ubuntu.com/3813-1/
2018-10-08
Published