OpenSSL < 0.9.8o / 1.0.0a Multiple Vulnerabilities

high Log Correlation Engine Plugin ID 801057

Synopsis

The remote web server is vulnerable to multiple attack vectors.

Description

Versions of OpenSSL earlier than 0.9.8o and 1.0.0a are potentially affected by multiple vulnerabilities :

- CMS structures containing 'OriginatorInfo' are mishandled which can cause the application to write to invalid memory addresses or free up memory twice. Note that this only affects OpenSSL with CMS code present. (CVE-2010-0742)

- When verification recovery fails for RSA keys, an uninitialized buffer with an undefined length is returned instead of an error code. Note that this only affects OpenSSL 1.0.0. (CVE-2010-1633)

Solution

Upgrade to OpenSSL 0.9.8o, 1.0.0, or later.

See Also

http://.openssl.org/news/secadv_20100601.txt

Plugin Details

Severity: High

ID: 801057

Family: Web Servers

Published: 6/2/2010

Nessus ID: 46801

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

Patch Publication Date: 6/1/2010

Vulnerability Publication Date: 6/1/2010

Reference Information

CVE: CVE-2010-0742, CVE-2010-1633

BID: 40502, 40503