Debian OpenSSL vulnerabilities
249 known vulnerabilities affecting debian/openssl.
Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2
Vulnerabilities
Page 6 of 13
CVE-2017-3733P3HIGHCVSS 7.5fixed in openssl 1.1.0e-1 (bookworm)2017
CVE-2017-3733 [HIGH] CVE-2017-3733: openssl - During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated...
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
Scope: local
bookworm: resolved (fixed in 1.1.0e-1)
bullseye: resolved (fixed in 1.1.0e-1)
forky: resolved
debian
CVE-2022-4304P3MEDIUMCVSS 5.9fixed in openssl 3.0.8-1 (bookworm)2022
CVE-2022-4304 [MEDIUM] CVE-2022-4304: openssl - A timing based side channel exists in the OpenSSL RSA Decryption implementation ...
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v
debian
CVE-2014-3513P3HIGHCVSS 7.1fixed in openssl 1.0.1j-1 (bookworm)2014
CVE-2014-3513 [HIGH] CVE-2014-3513: openssl - Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0....
Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted handshake message.
Scope: local
bookworm: resolved (fixed in 1.0.1j-1)
bullseye: resolved (fixed in 1.0.1j-1)
forky: resolved (fixed in 1.0.1j-1)
sid: resolved (fixed in 1.0.1j-1)
trixie: resolved (f
debian
CVE-2018-0739P3LOWCVSS 6.5fixed in libtomcrypt 1.18.2-1 (bookworm)2018
CVE-2018-0739 [MEDIUM] CVE-2018-0739: libtomcrypt - Constructed ASN.1 types with a recursive definition (such as can be found in PKC...
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0
debian
CVE-2014-8176P3HIGHCVSS 7.5fixed in openssl 1.0.1h-1 (bookworm)2014
CVE-2014-8176 [HIGH] CVE-2014-8176: openssl - The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0...
The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly ha
debian
CVE-2019-1559P3MEDIUMCVSS 5.9fixed in openssl 1.1.0b-2 (bookworm)2019
CVE-2019-1559 [MEDIUM] CVE-2019-1559: openssl - If an application encounters a fatal protocol error and then calls SSL_shutdown(...
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently b
debian
CVE-2007-5135P3LOWCVSS 10.0fixed in openssl 0.9.8e-9 (bookworm)2007
CVE-2007-5135 [CRITICAL] CVE-2007-5135: openssl - Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0...
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible
debian
CVE-2017-3736P3MEDIUMCVSS 6.5fixed in openssl 1.1.0g-1 (bookworm)2017
CVE-2017-3736 [MEDIUM] CVE-2017-3736: openssl - There is a carry propagating bug in the x86_64 Montgomery squaring procedure in ...
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very diffi
debian
CVE-2026-28388P3HIGHCVSS 7.5fixed in openssl 3.0.19-1~deb12u2 (bookworm)2026
CVE-2026-28388 [HIGH] CVE-2026-28388: openssl - Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is...
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When CRL processing and delta CRL processing is enabled during X.509 c
debian
CVE-2025-69420P3HIGHCVSS 7.5fixed in openssl 3.0.18-1~deb12u2 (bookworm)2025
CVE-2025-69420 [HIGH] CVE-2025-69420: openssl - Issue summary: A type confusion vulnerability exists in the TimeStamp Response v...
Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp
debian
CVE-2023-6129P3MEDIUMCVSS 6.5fixed in openssl 3.0.13-1~deb12u1 (bookworm)2023
CVE-2023-6129 [MEDIUM] CVE-2023-6129: openssl - Issue summary: The POLY1305 MAC (message authentication code) implementation con...
Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. Impact summary: If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various
debian
CVE-2016-7055P3LOWCVSS 5.9fixed in openssl 1.1.0c-1 (bookworm)2016
CVE-2016-7055 [MEDIUM] CVE-2016-7055: openssl - There is a carry propagating bug in the Broadwell-specific Montgomery multiplica...
There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the pri
debian
CVE-2017-3732P3HIGHCVSS 7.5fixed in openssl 1.1.0d-1 (bookworm)2017
CVE-2017-3732 [HIGH] CVE-2017-3732: openssl - There is a carry propagating bug in the x86_64 Montgomery squaring procedure in ...
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very d
debian
CVE-2014-3506P3MEDIUMCVSS 5.0fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3506 [MEDIUM] CVE-2014-3506: openssl - d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 befo...
d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via crafted DTLS handshake messages that trigger memory allocations corresponding to large length values.
Scope: local
bookworm: resolved (fixed in 1.0.1i-1)
bullseye: resolved (f
debian
CVE-2023-0401P3HIGHCVSS 7.5fixed in openssl 3.0.8-1 (bookworm)2023
CVE-2023-0401 [HIGH] CVE-2023-0401: openssl - A NULL pointer can be dereferenced when signatures are being verified on PKCS7 s...
A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check for the return value from the initialization funct
debian
CVE-2017-3738P3LOWCVSS 7.5fixed in openssl 1.1.0h-1 (bookworm)2017
CVE-2017-3738 [HIGH] CVE-2017-3738: openssl - There is an overflow bug in the AVX2 Montgomery multiplication procedure used in...
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work n
debian
CVE-2008-5077P3MEDIUMCVSS 5.8fixed in openssl 0.9.8g-15 (bookworm)2008
CVE-2008-5077 [MEDIUM] CVE-2008-5077: openssl - OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP...
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
Scope: local
bookworm: resolved (fixed in 0.9.8g-15)
bullseye: resolved (fixed in 0.9.8g-15)
forky: resolved (fixed in 0.9.8g-15)
s
debian
CVE-2014-3567P3HIGHCVSS 7.1fixed in openssl 1.0.1j-1 (bookworm)2014
CVE-2014-3567 [HIGH] CVE-2014-3567: openssl - Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9...
Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted session ticket that triggers an integrity-check failure.
Scope: local
bookworm: resolved (fixed in 1.0.1j-1)
bullseye: resolved (fixed in 1.0.1j-1)
for
debian
CVE-2014-8275P3MEDIUMCVSS 5.0fixed in openssl 1.0.1k-1 (bookworm)2014
CVE-2014-8275 [MEDIUM] CVE-2014-8275: openssl - OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not en...
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/
debian
CVE-2014-3570P3MEDIUMCVSS 5.0fixed in openssl 1.0.1k-1 (bookworm)2014
CVE-2014-3570 [MEDIUM] CVE-2014-3570: openssl - The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1....
The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c, and crypto/bn/bn_asm.c.
Scope:
debian