OpenSSL Security Restriction Bypass Vulnerability (CVE-2018-0733)
OpenSSL Security Restriction Bypass Vulnerability (CVE-2018-0733)
Release date:
Updated on:
Affected Systems:
OpenSSL Project OpenSSL 1.1.0-1.1.0g
Unaffected system:
OpenSSL Project OpenSSL 1.1.0h
Description:
Bugtraq id: 103517
CVE (CAN) ID: CVE-2018-0733
OpenSSL is an open-source SSL implementation that implements high-strength encryption for network communication.
OpenSSL 1.1.0-1.1.0g, a security vulnerability exists in the implementation of the PA-RISC CRYPTO_memcmp function. Attackers can bypass security restrictions by constructing messages. Only HP-UX PA-RISC is affected.
<* Source: Peter Waltenberg
Link: https://www.openssl.org/news/secadv/20180327.txt
*>
Suggestion:
Vendor patch:
OpenSSL Project
---------------
The OpenSSL Project has released a Security Bulletin (20180327) and corresponding patches for this purpose:
20180327: OpenSSL Security Advisory [27 Mar 2018]
Link: https://www.openssl.org/news/secadv/20180327.txt
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151607.htm