CVE-2023-6129Expected Behavior Violation in Openssl

Severity
6.5MEDIUMNVD
OSV5.3
EPSS
2.5%
top 14.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateFeb 13

Description

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. Impact summary: If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL for PowerPC CPUs res

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 2.2 | Impact: 4.2

Affected Packages23 packages

debiandebian/openssl< openssl 3.0.13-1~deb12u1 (bookworm)
CVEListV5openssl/openssl3.2.03.2.1+2
Alpineopenssl/openssl< 3.0.12-r2+6
Debianopenssl/openssl< 3.0.13-1~deb12u1+2
Ubuntuopenssl/openssl< 1.1.1f-1ubuntu2.21+1

Patches

🔴Vulnerability Details

4
OSV
openssl vulnerabilities2024-02-05
OSV
CVE-2023-6129: Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications runn2024-01-09
GHSA
GHSA-rj8q-prqp-jwfg: Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications runn2024-01-09
OSV
CVE-2023-6129: Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications runn2024-01-09

📋Vendor Advisories

10
CISA ICS
Siemens SCALANCE W7002025-02-13
Oracle
Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure SEC (OpenSSL) — CVE-2023-61292025-01-15
CISA ICS
Siemens SINEC NMS2024-11-14
CISA ICS
Siemens SINEC INS2024-11-14
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (OpenSSL) — CVE-2023-61292024-07-15
CVE-2023-6129 — Expected Behavior Violation in Openssl | cvebase