{ "CVE_data_meta" : { "ASSIGNER" : "openssl-security@openssl.org", "DATE_PUBLIC" : "2017-08-28T00:00:00", "ID" : "CVE-2017-3735", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "OpenSSL", "version" : { "version_data" : [ { "version_value" : "1.1.0" }, { "version_value" : "1.0.2" } ] } } ] }, "vendor_name" : "OpenSSL Software Foundation" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "out of bounds read" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[debian-lts-announce] 20171109 [SECURITY] [DLA-1157-1] openssl security update", "refsource" : "MLIST", "url" : "https://lists.debian.org/debian-lts-announce/2017/11/msg00011.html" }, { "name" : "https://github.com/openssl/openssl/commit/068b963bb7afc57f5bdd723de0dd15e7795d5822", "refsource" : "MISC", "url" : "https://github.com/openssl/openssl/commit/068b963bb7afc57f5bdd723de0dd15e7795d5822" }, { "name" : "https://www.openssl.org/news/secadv/20170828.txt", "refsource" : "CONFIRM", "url" : "https://www.openssl.org/news/secadv/20170828.txt" }, { "name" : "https://www.openssl.org/news/secadv/20171102.txt", "refsource" : "CONFIRM", "url" : "https://www.openssl.org/news/secadv/20171102.txt" }, { "name" : "https://security.netapp.com/advisory/ntap-20170927-0001/", "refsource" : "CONFIRM", "url" : "https://security.netapp.com/advisory/ntap-20170927-0001/" }, { "name" : "https://security.netapp.com/advisory/ntap-20171107-0002/", "refsource" : "CONFIRM", "url" : "https://security.netapp.com/advisory/ntap-20171107-0002/" }, { "name" : "https://www.tenable.com/security/tns-2017-14", "refsource" : "CONFIRM", "url" : "https://www.tenable.com/security/tns-2017-14" }, { "name" : "https://www.tenable.com/security/tns-2017-15", "refsource" : "CONFIRM", "url" : "https://www.tenable.com/security/tns-2017-15" }, { "name" : "https://support.apple.com/HT208331", "refsource" : "CONFIRM", "url" : "https://support.apple.com/HT208331" }, { "name" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html", "refsource" : "CONFIRM", "url" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html" }, { "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html", "refsource" : "CONFIRM", "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html" }, { "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html", "refsource" : "CONFIRM", "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html" }, { "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html", "refsource" : "CONFIRM", "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html" }, { "name" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html", "refsource" : "CONFIRM", "url" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html" }, { "name" : "DSA-4017", "refsource" : "DEBIAN", "url" : "https://www.debian.org/security/2017/dsa-4017" }, { "name" : "DSA-4018", "refsource" : "DEBIAN", "url" : "https://www.debian.org/security/2017/dsa-4018" }, { "name" : "FreeBSD-SA-17:11", "refsource" : "FREEBSD", "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-17:11.openssl.asc" }, { "name" : "GLSA-201712-03", "refsource" : "GENTOO", "url" : "https://security.gentoo.org/glsa/201712-03" }, { "name" : "RHSA-2018:3221", "refsource" : "REDHAT", "url" : "https://access.redhat.com/errata/RHSA-2018:3221" }, { "name" : "RHSA-2018:3505", "refsource" : "REDHAT", "url" : "https://access.redhat.com/errata/RHSA-2018:3505" }, { "name" : "USN-3611-2", "refsource" : "UBUNTU", "url" : "https://usn.ubuntu.com/3611-2/" }, { "name" : "100515", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/100515" }, { "name" : "1039726", "refsource" : "SECTRACK", "url" : "http://www.securitytracker.com/id/1039726" } ] } }