Debian OpenSSL vulnerabilities
249 known vulnerabilities affecting debian/openssl.
Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2
Vulnerabilities
Page 11 of 13
CVE-2015-3196P4MEDIUMCVSS 4.3fixed in openssl 1.0.2d-1 (bookworm)2015
CVE-2015-3196 [MEDIUM] CVE-2015-3196: openssl - ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 bef...
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
Scope: local
bookworm: resolved (fixed in 1.0
debian
CVE-2009-1387P4LOWCVSS 5.0fixed in openssl 0.9.8k-2 (bookworm)2009
CVE-2009-1387 [MEDIUM] CVE-2009-1387: openssl - The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before...
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."
Scope: local
bookworm: resolved (fixed in 0.9.8k-2)
bullseye: resolved (fixed in 0.9.8k-2)
forky: res
debian
CVE-2009-4355P4LOWCVSS 5.0fixed in openssl 0.9.8k-8 (bookworm)2009
CVE-2009-4355 [MEDIUM] CVE-2009-4355: openssl - Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in Open...
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a relat
debian
CVE-2023-0466P4MEDIUMCVSS 5.3fixed in openssl 3.0.9-1 (bookworm)2023
CVE-2023-0466 [MEDIUM] CVE-2023-0466: openssl - The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable ...
The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. However the implementation of the function does not enable the check which allows certificates with invalid or incorrect policies to pass the certificate verification. As suddenly enabling the policy check could break exis
debian
CVE-2023-0465P4MEDIUMCVSS 5.3fixed in openssl 3.0.9-1 (bookworm)2023
CVE-2023-0465 [MEDIUM] CVE-2023-0465: openssl - Applications that use a non-default option when verifying certificates may be vu...
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid cer
debian
CVE-2016-0702P4MEDIUMCVSS 5.1fixed in openssl 1.0.2g-1 (bookworm)2016
CVE-2016-0702 [MEDIUM] CVE-2016-0702: openssl - The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0...
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-
debian
CVE-2024-4603P4MEDIUMCVSS 5.3fixed in openssl 3.0.14-1~deb12u1 (bookworm)2024
CVE-2024-4603 [MEDIUM] CVE-2024-4603: openssl - Issue summary: Checking excessively long DSA keys or parameters may be very slow...
Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to
debian
CVE-2025-15469P4LOWCVSS 5.5fixed in openssl 3.5.5-1 (forky)2025
CVE-2025-15469 [MEDIUM] CVE-2025-15469: openssl - Issue summary: The 'openssl dgst' command-line tool silently truncates input dat...
Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error. Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire file is authenticated while trailing data bey
debian
CVE-2003-0131P4HIGHCVSS 7.5fixed in openssl 0.9.7b-1 (bookworm)2003
CVE-2003-0131 [HIGH] CVE-2003-0131: openssl - The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a all...
The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associate
debian
CVE-2009-2409P4LOWCVSS 5.1fixed in nss 3.12.3-1 (bookworm)2009
CVE-2009-2409 [MEDIUM] CVE-2009-2409: nss - The Network Security Services (NSS) library before 3.12.3, as used in Firefox; G...
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is
debian
CVE-2005-2969P4LOWCVSS 5.0fixed in openssl 0.9.8-3 (bookworm)2005
CVE-2005-2969 [MEDIUM] CVE-2005-2969: openssl - The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 befor...
The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.
S
debian
CVE-2006-4339P4MEDIUMCVSS 4.3fixed in openssl 0.9.8b-3 (bookworm)2006
CVE-2006-4339 [MEDIUM] CVE-2006-4339: openssl - OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using a...
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
Scope: local
bookworm: r
debian
CVE-2015-0288P4MEDIUMCVSS 5.0fixed in openssl 1.0.1k-2 (bookworm)2015
CVE-2015-0288 [MEDIUM] CVE-2015-0288: openssl - The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8z...
The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service (NULL pointer dereference and application crash) via an invalid certificate key.
Scope: local
bookworm: resolved (fixed in 1.0.1k-2)
bullseye: resolved (fixed in 1.0.1k
debian
CVE-2006-7250P4MEDIUMCVSS 5.0fixed in openssl 1.0.0h-1 (bookworm)2006
CVE-2006-7250 [MEDIUM] CVE-2006-7250: openssl - The mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and earlie...
The mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message.
Scope: local
bookworm: resolved (fixed in 1.0.0h-1)
bullseye: resolved (fixed in 1.0.0h-1)
forky: resolved (fixed in 1.0.0h-1)
sid: resolved (fixed in 1.0
debian
CVE-2012-0027P4MEDIUMCVSS 5.0fixed in openssl 1.0.0f-1 (bookworm)2012
CVE-2012-0027 [MEDIUM] CVE-2012-0027: openssl - The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parame...
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Scope: local
bookworm: resolved (fixed in 1.0.0f-1)
bullseye: resolved (fixed in 1.0.0f-1)
forky: resolved (fixed in 1.0.0f-1)
sid: resolved (fixe
debian
CVE-2015-1794P4MEDIUMCVSS 5.0fixed in openssl 1.0.2e-1 (bookworm)2015
CVE-2015-1794 [MEDIUM] CVE-2015-1794: openssl - The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0....
The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.
Scope: local
bookworm: resolved (fixed in 1.0.2e-1)
bullseye: resolved (fixed in 1.0.2e-1)
forky: resolved (fixed in 1.0.2e-1)
sid:
debian
CVE-2004-0112P4MEDIUMCVSS 5.0fixed in openssl 0.9.7d-1 (bookworm)2004
CVE-2004-0112 [MEDIUM] CVE-2004-0112: openssl - The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using K...
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 0.9.7d-1)
bulls
debian
CVE-2007-6755P4LOWCVSS 5.8fixed in openssl 1.1.0b-2 (bookworm)2007
CVE-2007-6755 [MEDIUM] CVE-2007-6755: openssl - The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic R...
The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a pre
debian
CVE-2016-2178P4LOWCVSS 5.5fixed in openssl 1.0.2i-1 (bookworm)2016
CVE-2016-2178 [MEDIUM] CVE-2016-2178: openssl - The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h d...
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
Scope: local
bookworm: resolved (fixed in 1.0.2i-1)
bullseye: resolved (fixed in 1.0.2i-1)
forky: resolved (fixed in 1.0.2i-1
debian
CVE-2016-7056P4MEDIUMCVSS 5.5fixed in openssl 1.0.2a-1 (bookworm)2016
CVE-2016-7056 [MEDIUM] CVE-2016-7056: openssl - A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a m...
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
Scope: local
bookworm: resolved (fixed in 1.0.2a-1)
bullseye: resolved (fixed in 1.0.2a-1)
forky: resolved (fixed in 1.0.2a-1)
sid: resolved (fixed in 1.0.2a-1)
trixie: resolved (fixed in 1.0.2a-1)
debian