Debian OpenSSL vulnerabilities
249 known vulnerabilities affecting debian/openssl.
Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2
Vulnerabilities
Page 8 of 13
CVE-2024-12797P3LOWCVSS 6.3fixed in openssl 3.4.1-1 (forky)2024
CVE-2024-12797 [MEDIUM] CVE-2024-12797: openssl - Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a se...
Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set. Impact summary: TLS and DTLS connections using raw public keys may be vulnerable to man-in-middle attacks when server authenticat
debian
CVE-2015-1792P4MEDIUMCVSS 5.0fixed in openssl 1.0.2b-1 (bookworm)2015
CVE-2015-1792 [MEDIUM] CVE-2015-1792: openssl - The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1...
The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function.
Scope: local
bookworm: re
debian
CVE-2015-1788P4MEDIUMCVSS 4.3fixed in openssl 1.0.2b-1 (bookworm)2015
CVE-2015-1788 [MEDIUM] CVE-2015-1788: openssl - The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1....
The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b does not properly handle ECParameters structures in which the curve is over a malformed binary polynomial field, which allows remote attackers to cause a denial of service (infinite loop) via a session that uses an Elliptic
debian
CVE-2023-0216P3HIGHCVSS 7.5fixed in openssl 3.0.8-1 (bookworm)2023
CVE-2023-0216 [HIGH] CVE-2023-0216: openssl - An invalid pointer dereference on read can be triggered when an application trie...
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applicat
debian
CVE-2025-11187P3LOWCVSS 6.1fixed in openssl 3.5.5-1 (forky)2025
CVE-2025-11187 [MEDIUM] CVE-2025-11187: openssl - Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which c...
Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. Th
debian
CVE-2015-3197P3MEDIUMCVSS 5.9fixed in openssl 1.0.0c-2 (bookworm)2015
CVE-2015-3197 [MEDIUM] CVE-2015-3197: openssl - ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not pr...
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
Scope: local
bookworm: resolved (fixed in 1
debian
CVE-2014-3568P3MEDIUMCVSS 4.3fixed in openssl 1.0.1j-1 (bookworm)2014
CVE-2014-3568 [MEDIUM] CVE-2014-3568: openssl - OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not pr...
OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.
Scope: local
bookworm: resolved (fixed in 1.0.1j-1)
bullseye: resolved (fixed in 1.0.1j-1)
forky: resolved (fixed
debian
CVE-2025-9232P3MEDIUMCVSS 5.9fixed in openssl 3.0.17-1~deb12u3 (bookworm)2025
CVE-2025-9232 [MEDIUM] CVE-2025-9232: openssl - Issue summary: An application using the OpenSSL HTTP client API functions may tr...
Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP cl
debian
CVE-2015-0293P4MEDIUMCVSS 5.0fixed in openssl 1.0.0c-2 (bookworm)2015
CVE-2015-0293 [MEDIUM] CVE-2015-0293: openssl - The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 b...
The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (s2_lib.c assertion failure and daemon exit) via a crafted CLIENT-MASTER-KEY message.
Scope: local
bookworm: resolved (fixed in 1.0.0c-2)
bullseye: resolved (fixed in 1.0.0c-2)
forky: resolved (fix
debian
CVE-2020-1971P3MEDIUMCVSS 5.9fixed in openssl 1.1.1i-1 (bookworm)2020
CVE-2020-1971 [MEDIUM] CVE-2020-1971: openssl - The X.509 GeneralName type is a generic type for representing different types of...
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer d
debian
CVE-2015-1790P4MEDIUMCVSS 5.0fixed in openssl 1.0.2b-1 (bookworm)2015
CVE-2015-1790 [MEDIUM] CVE-2015-1790: openssl - The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8z...
The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.
Scope: local
bookworm: resolved (fi
debian
CVE-2009-3245P4LOWCVSS 10.0fixed in openssl 0.9.8m-1 (bookworm)2009
CVE-2009-3245 [CRITICAL] CVE-2009-3245: openssl - OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand fun...
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.
Scope: local
bookworm: resolved (fixed in 0.9.8m-1)
bullseye: resolved (fixed in 0.9.8m-1)
forky: reso
debian
CVE-2006-2937P4HIGHCVSS 7.8fixed in openssl 0.9.8c-2 (bookworm)2006
CVE-2006-2937 [HIGH] CVE-2006-2937: openssl - OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to c...
OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.
Scope: local
bookworm: resolved (fixed in 0.9.8c-2)
bullseye: resolved (fixed in 0.9.8c-2)
forky: resolved (fixed in 0.9.8c-2)
sid: resolved (f
debian
CVE-2014-3571P4MEDIUMCVSS 5.0fixed in openssl 1.0.1k-1 (bookworm)2014
CVE-2014-3571 [MEDIUM] CVE-2014-3571: openssl - OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remo...
OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message that is processed with a different read operation for the handshake header than for the handshake body, related to the dtls1_get_record function in d1_pkt.c and the ssl3_
debian
CVE-2015-0286P4MEDIUMCVSS 5.0fixed in openssl 1.0.1k-2 (bookworm)2015
CVE-2015-0286 [MEDIUM] CVE-2015-0286: openssl - The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1....
The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted X.509 certificate to an endpoint that uses the certi
debian
CVE-2010-5298P4LOWCVSS 4.0fixed in openssl 1.0.1g-3 (bookworm)2010
CVE-2010-5298 [MEDIUM] CVE-2010-5298: openssl - Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1....
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
Scope: local
bookworm: resolved (fixed in 1.0.1g-3)
bullseye: resol
debian
CVE-2018-0735P4MEDIUMCVSS 5.9fixed in openssl 1.1.1a-1 (bookworm)2018
CVE-2018-0735 [MEDIUM] CVE-2018-0735: openssl - The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timin...
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
Scope: local
bookworm: resolved (fixed in 1.1.1a-1)
bullseye: resolved (fixed in 1.1.1a-
debian
CVE-2019-1549P4MEDIUMCVSS 5.3fixed in openssl 1.1.1d-1 (bookworm)2019
CVE-2019-1549 [MEDIUM] CVE-2019-1549: openssl - OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was int...
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high pre
debian
CVE-2021-4160P4LOWCVSS 3.7fixed in openssl 1.1.1m-1 (bookworm)2021
CVE-2021-4160 [LOW] CVE-2021-4160: openssl - There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Ma...
There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would
debian
CVE-2006-2940P4HIGHCVSS 7.8fixed in openssl 0.9.8c-2 (bookworm)2006
CVE-2006-2940 [HIGH] CVE-2006-2940: openssl - OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows at...
OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.
Scope: local
bookworm: resolved (fixed in 0.9.8c-
debian