Debian OpenSSL vulnerabilities
249 known vulnerabilities affecting debian/openssl.
Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2
Vulnerabilities
Page 3 of 13
CVE-2016-6304P3HIGHCVSS 7.5fixed in openssl 1.0.2i-1 (bookworm)2016
CVE-2016-6304 [HIGH] CVE-2016-6304: openssl - Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i,...
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
Scope: local
bookworm: resolved (fixed in 1.0.2i-1)
bullseye: resolved (fixed in 1.0.2i-1)
forky: resolved (fixed in 1.0.2i-1)
sid: resolved (fixed in
debian
CVE-2014-3512P3HIGHCVSS 7.5fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3512 [HIGH] CVE-2014-3512: openssl - Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in O...
Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid SRP (1) g, (2) A, or (3) B parameter.
Scope: local
bookworm: resolved (fixed in 1.0.1i-1)
bullseye: resolved (fixed in 1.0.1i-1)
forky
debian
CVE-2006-3738P3CRITICALCVSS 10.0fixed in openssl 0.9.8c-2 (bookworm)2006
CVE-2006-3738 [CRITICAL] CVE-2006-3738: openssl - Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0...
Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.
Scope: local
bookworm: resolved (fixed in 0.9.8c-2)
bullseye: resolved (fixed in 0.9.8c-2)
forky: resolved (fixed in 0.9.8c-2)
sid: resolved (fixed in 0.9
debian
CVE-2016-0799P3CRITICALCVSS 9.8fixed in openssl 1.0.2g-1 (bookworm)2016
CVE-2016-0799 [CRITICAL] CVE-2016-0799: openssl - The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1...
The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability
debian
CVE-2015-0292P3HIGHCVSS 7.5fixed in openssl 1.0.1h-1 (bookworm)2015
CVE-2015-0292 [HIGH] CVE-2015-0292: openssl - Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the...
Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted base64 data that triggers a buffer overflow.
Scope: local
b
debian
CVE-2012-2686P3MEDIUMCVSS 5.0PoCfixed in openssl 1.0.1e-1 (bookworm)2012
CVE-2012-2686 [MEDIUM] CVE-2012-2686: openssl - crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and ...
crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.
Scope: local
bookworm: resolved (fixed in 1.0.1e-1)
bullseye: resolved (fixed in 1.0.1e-1)
forky: resolved (fixed in 1.0.1e-1)
sid: resolved (
debian
CVE-2016-6303P3CRITICALCVSS 9.8fixed in openssl 1.0.2i-1 (bookworm)2016
CVE-2016-6303 [CRITICAL] CVE-2016-6303: openssl - Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSS...
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.0.2i-1)
bullseye: resolved (fixed in 1.0.2i-1)
forky: resolved (fix
debian
CVE-2021-3450P3HIGHCVSS 7.4fixed in openssl 1.1.1k-1 (bookworm)2021
CVE-2021-3450 [HIGH] CVE-2021-3450: openssl - The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certi...
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check
debian
CVE-2010-3864P3HIGHCVSS 7.6fixed in openssl 0.9.8o-3 (bookworm)2010
CVE-2010-3864 [HIGH] CVE-2010-3864: openssl - Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0...
Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers a heap-based buffer overflow, related to (1) the TLS server name extension and (2) elliptic curve cryptography.
Scope: l
debian
CVE-2016-8610P3HIGHCVSS 7.5fixed in openssl 1.0.2j-1 (bookworm)2016
CVE-2016-8610 [HIGH] CVE-2016-8610: openssl - A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h...
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
Scope: local
bookworm: resolve
debian
CVE-2021-3449P3MEDIUMCVSS 5.9fixed in openssl 1.1.1k-1 (bookworm)2021
CVE-2021-3449 [MEDIUM] CVE-2021-3449: openssl - An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation Clie...
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denia
debian
CVE-2003-0545P3CRITICALCVSS 9.8fixed in openssl 0.9.7c (bookworm)2003
CVE-2003-0545 [CRITICAL] CVE-2003-0545: openssl - Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a de...
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.
Scope: local
bookworm: resolved (fixed in 0.9.7c)
bullseye: resolved (fixed in 0.9.7c)
forky: resolved (fixed in 0.9.7c)
sid: resolved (fixed in 0.9.7c)
trix
debian
CVE-2015-0204P3MEDIUMCVSS 4.3fixed in openssl 1.0.1k-1 (bookworm)2015
CVE-2015-0204 [MEDIUM] CVE-2015-0204: openssl - The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0...
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the "FREAK" issue. NOTE: the scope of this CVE is only client cod
debian
CVE-2009-1379P3LOWCVSS 5.0PoCfixed in openssl 0.9.8k-1 (bookworm)2009
CVE-2009-1379 [MEDIUM] CVE-2009-1379: openssl - Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in...
Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.
Scope: local
bookworm: reso
debian
CVE-2016-0705P3CRITICALCVSS 9.8fixed in openssl 1.0.2g-1 (bookworm)2016
CVE-2016-0705 [CRITICAL] CVE-2016-0705: openssl - Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_amet...
Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.
Scope: local
bookworm: resolved (fixed in 1.0.2g-1)
bullseye: resolved (fixed i
debian
CVE-2024-2511P3MEDIUMCVSS 5.9fixed in openssl 3.0.14-1~deb12u1 (bookworm)2024
CVE-2024-2511 [MEDIUM] CVE-2024-2511: openssl - Issue summary: Some non-default TLS server configurations can cause unbounded me...
Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not
debian
CVE-2015-3193P3HIGHCVSS 7.5fixed in openssl 1.0.2e-1 (bookworm)2015
CVE-2015-3193 [HIGH] CVE-2015-3193: openssl - The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenS...
The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2
debian
CVE-2010-0740P4MEDIUMCVSS 5.0PoCfixed in openssl 0.9.8n-1 (bookworm)2010
CVE-2010-0740 [MEDIUM] CVE-2010-0740: openssl - The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m al...
The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fix
debian
CVE-2016-2105P3HIGHCVSS 7.5fixed in openssl 1.0.2h-1 (bookworm)2016
CVE-2016-2105 [HIGH] CVE-2016-2105: openssl - Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in Open...
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
Scope: local
bookworm: resolved (fixed in 1.0.2h-1)
bullseye: resolved (fixed in 1.0.2h-1)
forky: resolved (fixed in 1.0.2h-1)
sid: res
debian
CVE-2011-4109P3CRITICALCVSS 9.3fixed in openssl 1.0.0c-1 (bookworm)2011
CVE-2011-4109 [CRITICAL] CVE-2011-4109: openssl - Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLIC...
Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.
Scope: local
bookworm: resolved (fixed in 1.0.0c-1)
bullseye: resolved (fixed in 1.0.0c-1)
forky: resolved (fixed in 1.0.0c-1)
sid: resolved (fixed in 1.0.0c-1)
trixie: re
debian