Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.117581
Category:General
Title:OpenSSL Security Bypass Vulnerability (20180327) - Linux
Summary:OpenSSL is prone to a security bypass vulnerability.
Description:Summary:
OpenSSL is prone to a security bypass vulnerability.

Vulnerability Insight:
Because of an implementation bug the PA-RISC CRYPTO_memcmp
function is effectively reduced to only comparing the least significant bit of each byte. This
allows an attacker to forge messages that would be considered as authenticated in an amount of
tries lower than that guaranteed by the security claims of the scheme.

Affected Software/OS:
OpenSSL version 1.1.0 through 1.1.0g.

The affected module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC
targets are affected.

Solution:
Update to version 1.1.0h or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-0733
BugTraq ID: 103517
http://www.securityfocus.com/bid/103517
https://security.gentoo.org/glsa/201811-21
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
http://www.securitytracker.com/id/1040576
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.