Уязвимость CVE-2014-3508: Информация

Описание

The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when pretty printing is used, does not ensure the presence of '\0' characters, which allows context-dependent attackers to obtain sensitive information from process stack memory by reading output from X509_name_oneline, X509_name_print_ex, and unspecified other functions.

Важность: MEDIUM (4,3)

Опубликовано: 14 августа 2014 г.
Изменено: 7 ноября 2023 г.
Идентификатор типа ошибки: CWE-200

Исправленные пакеты

Имя пакета
Ветка
Исправлено в версии
Версия в репозитории
Errata ID
№ Задания
Состояние
openssl10p91.0.1j-alt11.0.2u-alt1.p9.2ALT-PU-2014-2312-1133582Исправлено
openssl10c9f21.0.1j-alt11.0.2u-alt1.p9.1ALT-PU-2014-2312-1133582Исправлено
openssl10c71.0.1j-alt1.M70C.11.0.1u-alt0.M70C.1ALT-PU-2014-2316-1133754Исправлено

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
https://www.openssl.org/news/secadv_20140806.txt
  • Vendor Advisory
http://www.tenable.com/security/tns-2014-06
    http://linux.oracle.com/errata/ELSA-2014-1053.html
      60687
        59221
          60824
            60917
              NetBSD-SA2014-008
                http://aix.software.ibm.com/aix/efixes/security/openssl_advisory10.asc
                  60938
                    60861
                      60921
                        HPSBGN03099
                          openSUSE-SU-2014:1052
                            RHSA-2014:1297
                              DSA-2998
                                HPSBUX03095
                                  HPSBOV03099
                                    RHSA-2014:1256
                                      http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-372998.htm
                                        61775
                                          61959
                                            http://www-01.ibm.com/support/docview.wss?uid=swg21686997
                                              http://www-01.ibm.com/support/docview.wss?uid=swg21682293
                                                59756
                                                  HPSBMU03260
                                                    HPSBMU03267
                                                      SSRT101846
                                                        SUSE-SU-2015:0578
                                                          HPSBMU03304
                                                            https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
                                                              https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
                                                                HPSBMU03263
                                                                  HPSBMU03261
                                                                    openSUSE-SU-2016:0640
                                                                      FreeBSD-SA-14:18
                                                                        [syslog-ng-announce] 20140910 syslog-ng Premium Edition 5 LTS (5.0.6a) has been released
                                                                          https://bugzilla.redhat.com/show_bug.cgi?id=1127490
                                                                            59700
                                                                              58962
                                                                                FEDORA-2014-9308
                                                                                  FEDORA-2014-9301
                                                                                    http://linux.oracle.com/errata/ELSA-2014-1052.html
                                                                                      openssl-cve20143508-info-disc(95165)
                                                                                        https://support.citrix.com/article/CTX216642
                                                                                          59710
                                                                                            59743
                                                                                              60022
                                                                                                60221
                                                                                                  60410
                                                                                                    60493
                                                                                                      60684
                                                                                                        60778
                                                                                                          60803
                                                                                                            61017
                                                                                                              61100
                                                                                                                61171
                                                                                                                  61184
                                                                                                                    61214
                                                                                                                      61250
                                                                                                                        61392
                                                                                                                          http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15571.html
                                                                                                                            MDVSA-2014:158
                                                                                                                              69075
                                                                                                                                1030693
                                                                                                                                  http://www-01.ibm.com/support/docview.wss?uid=nas8N1020240
                                                                                                                                    http://www-01.ibm.com/support/docview.wss?uid=swg21681752
                                                                                                                                      http://www-01.ibm.com/support/docview.wss?uid=swg21683389
                                                                                                                                        https://blogs.oracle.com/sunsecurity/entry/cve_2014_3508_information_disclosure
                                                                                                                                          https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=0042fb5fd1c9d257d713b15a1f45da05cf5c1c87
                                                                                                                                              1. Конфигурация 1

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8m:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8n:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8p:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8u:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8za:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8m:beta1:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8s:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8l:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8r:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8t:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8o:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8q:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8w:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8v:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8y:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:0.9.8x:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*

                                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*