OpenSSL < 0.9.8o / 1.0.0a Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 5559


The remote web server is vulnerable to multiple attack vectors.


Versions of OpenSSL earlier than 0.9.8o and 1.0.0a are potentially affected by multiple vulnerabilities :

- CMS structures containing 'OriginatorInfo' are mishandled which can cause the application to write to invalid memory addresses or free up memory twice. Note that this only affects OpenSSL with CMS code present. (CVE-2010-0742)

- When verification recovery fails for RSA keys, an uninitialized buffer with an undefined length is returned instead of an error code. Note that this only affects OpenSSL 1.0.0. (CVE-2010-1633)


Upgrade to OpenSSL 0.9.8o, 1.0.0, or later.

See Also

Plugin Details

Severity: High

ID: 5559

Family: Web Servers

Published: 2010/06/02

Updated: 2019/03/06

Dependencies: 5563

Nessus ID: 46801

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:openssl:openssl

Patch Publication Date: 2010/06/01

Vulnerability Publication Date: 2010/06/01

Reference Information

CVE: CVE-2010-0742, CVE-2010-1633

BID: 40502, 40503