CVE-2018-0733

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).

References

http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html

http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

http://www.securityfocus.com/bid/103517

http://www.securitytracker.com/id/1040576

https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=56d5a4bfcaf37fa420aef2bb881aa55e61cf5f2f

https://security.gentoo.org/glsa/201811-21

https://security.netapp.com/advisory/ntap-20180330-0002/

https://www.openssl.org/news/secadv/20180327.txt

https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html

https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html

https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html

https://www.tenable.com/security/tns-2018-04

https://www.tenable.com/security/tns-2018-06

https://www.tenable.com/security/tns-2018-07

Details

Source: MITRE

Published: 2018-03-27

Updated: 2020-08-24

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 2.2

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from 1.1.0 to 1.1.0g (inclusive)

Tenable Plugins

View all (8 total)

IDNameProductFamilySeverity
131184Oracle Enterprise Manager Ops Center (Jan 2019 CPU)NessusMisc.
critical
120390Fedora 28 : 1:openssl (2018-49651b2236)NessusFedora Local Security Checks
medium
119275GLSA-201811-21 : OpenSSL: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
112092Amazon Linux AMI : openssl (ALAS-2018-1065)NessusAmazon Linux Local Security Checks
medium
111333Oracle Secure Global Desktop Multiple Vulnerabilities (July 2018 CPU)NessusMisc.
critical
108776Fedora 27 : 1:openssl (2018-76afaf1961)NessusFedora Local Security Checks
medium
108775Fedora 26 : 1:openssl (2018-40dc8b8b16)NessusFedora Local Security Checks
medium
106563Tenable SecurityCenter OpenSSL 1.0.2 < 1.0.2n Multiple VulnerabilitiesNessusMisc.
medium