cvelist/2017/3xxx/CVE-2017-3731.json
Your Name f6e31027cb Submitter: Bill Situ <Bill.Situ@oracle.com>
On branch cna/oracle/jan2018cpu
  Changes to be committed:

	modified:   2013/2xxx/CVE-2013-2566.json
	modified:   2014/0xxx/CVE-2014-0114.json
	modified:   2014/7xxx/CVE-2014-7817.json
	modified:   2014/9xxx/CVE-2014-9402.json
	modified:   2015/0xxx/CVE-2015-0293.json
	modified:   2015/1xxx/CVE-2015-1472.json
	modified:   2015/2xxx/CVE-2015-2808.json
	modified:   2015/3xxx/CVE-2015-3195.json
	modified:   2015/3xxx/CVE-2015-3253.json
	modified:   2015/4xxx/CVE-2015-4852.json
	modified:   2015/7xxx/CVE-2015-7501.json
	modified:   2015/7xxx/CVE-2015-7547.json
	modified:   2015/7xxx/CVE-2015-7940.json
	modified:   2016/0xxx/CVE-2016-0635.json
	modified:   2016/0xxx/CVE-2016-0703.json
	modified:   2016/0xxx/CVE-2016-0704.json
	modified:   2016/0xxx/CVE-2016-0800.json
	modified:   2016/1xxx/CVE-2016-1181.json
	modified:   2016/1xxx/CVE-2016-1182.json
	modified:   2016/2xxx/CVE-2016-2105.json
	modified:   2016/2xxx/CVE-2016-2106.json
	modified:   2016/2xxx/CVE-2016-2107.json
	modified:   2016/2xxx/CVE-2016-2109.json
	modified:   2016/2xxx/CVE-2016-2177.json
	modified:   2016/2xxx/CVE-2016-2178.json
	modified:   2016/2xxx/CVE-2016-2179.json
	modified:   2016/2xxx/CVE-2016-2180.json
	modified:   2016/2xxx/CVE-2016-2181.json
	modified:   2016/2xxx/CVE-2016-2182.json
	modified:   2016/2xxx/CVE-2016-2183.json
	modified:   2016/2xxx/CVE-2016-2518.json
	modified:   2016/2xxx/CVE-2016-2550.json
	modified:   2016/4xxx/CVE-2016-4449.json
	modified:   2016/5xxx/CVE-2016-5385.json
	modified:   2016/5xxx/CVE-2016-5387.json
	modified:   2016/6xxx/CVE-2016-6302.json
	modified:   2016/6xxx/CVE-2016-6303.json
	modified:   2016/6xxx/CVE-2016-6304.json
	modified:   2016/6xxx/CVE-2016-6305.json
	modified:   2016/6xxx/CVE-2016-6306.json
	modified:   2016/6xxx/CVE-2016-6307.json
	modified:   2016/6xxx/CVE-2016-6308.json
	modified:   2016/6xxx/CVE-2016-6309.json
	modified:   2016/7xxx/CVE-2016-7052.json
	modified:   2016/7xxx/CVE-2016-7055.json
	modified:   2016/7xxx/CVE-2016-7977.json
	modified:   2016/8xxx/CVE-2016-8735.json
	modified:   2016/9xxx/CVE-2016-9878.json
	modified:   2017/0xxx/CVE-2017-0781.json
	modified:   2017/0xxx/CVE-2017-0782.json
	modified:   2017/0xxx/CVE-2017-0783.json
	modified:   2017/0xxx/CVE-2017-0785.json
	modified:   2017/10xxx/CVE-2017-10068.json
	modified:   2017/10xxx/CVE-2017-10262.json
	modified:   2017/10xxx/CVE-2017-10273.json
	modified:   2017/10xxx/CVE-2017-10282.json
	modified:   2017/10xxx/CVE-2017-10301.json
	modified:   2017/10xxx/CVE-2017-10352.json
	modified:   2017/12xxx/CVE-2017-12617.json
	modified:   2017/13xxx/CVE-2017-13077.json
	modified:   2017/13xxx/CVE-2017-13078.json
	modified:   2017/13xxx/CVE-2017-13079.json
	modified:   2017/13xxx/CVE-2017-13080.json
	modified:   2017/13xxx/CVE-2017-13081.json
	modified:   2017/13xxx/CVE-2017-13082.json
	modified:   2017/3xxx/CVE-2017-3730.json
	modified:   2017/3xxx/CVE-2017-3731.json
	modified:   2017/3xxx/CVE-2017-3732.json
	modified:   2017/3xxx/CVE-2017-3733.json
	modified:   2017/3xxx/CVE-2017-3735.json
	modified:   2017/3xxx/CVE-2017-3736.json
	modified:   2017/3xxx/CVE-2017-3737.json
	modified:   2017/3xxx/CVE-2017-3738.json
	modified:   2017/5xxx/CVE-2017-5461.json
	modified:   2017/5xxx/CVE-2017-5645.json
	modified:   2017/5xxx/CVE-2017-5664.json
	modified:   2017/5xxx/CVE-2017-5715.json
	modified:   2017/9xxx/CVE-2017-9072.json
	modified:   2017/9xxx/CVE-2017-9798.json
	modified:   2018/2xxx/CVE-2018-2560.json
	modified:   2018/2xxx/CVE-2018-2561.json
	modified:   2018/2xxx/CVE-2018-2562.json
	modified:   2018/2xxx/CVE-2018-2564.json
	modified:   2018/2xxx/CVE-2018-2565.json
	modified:   2018/2xxx/CVE-2018-2566.json
	modified:   2018/2xxx/CVE-2018-2567.json
	modified:   2018/2xxx/CVE-2018-2568.json
	modified:   2018/2xxx/CVE-2018-2569.json
	modified:   2018/2xxx/CVE-2018-2570.json
	modified:   2018/2xxx/CVE-2018-2571.json
	modified:   2018/2xxx/CVE-2018-2573.json
	modified:   2018/2xxx/CVE-2018-2574.json
	modified:   2018/2xxx/CVE-2018-2575.json
	modified:   2018/2xxx/CVE-2018-2576.json
	modified:   2018/2xxx/CVE-2018-2577.json
	modified:   2018/2xxx/CVE-2018-2578.json
	modified:   2018/2xxx/CVE-2018-2579.json
	modified:   2018/2xxx/CVE-2018-2580.json
	modified:   2018/2xxx/CVE-2018-2581.json
	modified:   2018/2xxx/CVE-2018-2582.json
	modified:   2018/2xxx/CVE-2018-2583.json
	modified:   2018/2xxx/CVE-2018-2584.json
	modified:   2018/2xxx/CVE-2018-2585.json
	modified:   2018/2xxx/CVE-2018-2586.json
	modified:   2018/2xxx/CVE-2018-2588.json
	modified:   2018/2xxx/CVE-2018-2589.json
	modified:   2018/2xxx/CVE-2018-2590.json
	modified:   2018/2xxx/CVE-2018-2591.json
	modified:   2018/2xxx/CVE-2018-2592.json
	modified:   2018/2xxx/CVE-2018-2593.json
	modified:   2018/2xxx/CVE-2018-2594.json
	modified:   2018/2xxx/CVE-2018-2595.json
	modified:   2018/2xxx/CVE-2018-2596.json
	modified:   2018/2xxx/CVE-2018-2597.json
	modified:   2018/2xxx/CVE-2018-2599.json
	modified:   2018/2xxx/CVE-2018-2600.json
	modified:   2018/2xxx/CVE-2018-2601.json
	modified:   2018/2xxx/CVE-2018-2602.json
	modified:   2018/2xxx/CVE-2018-2603.json
	modified:   2018/2xxx/CVE-2018-2604.json
	modified:   2018/2xxx/CVE-2018-2605.json
	modified:   2018/2xxx/CVE-2018-2606.json
	modified:   2018/2xxx/CVE-2018-2607.json
	modified:   2018/2xxx/CVE-2018-2608.json
	modified:   2018/2xxx/CVE-2018-2609.json
	modified:   2018/2xxx/CVE-2018-2610.json
	modified:   2018/2xxx/CVE-2018-2611.json
	modified:   2018/2xxx/CVE-2018-2612.json
	modified:   2018/2xxx/CVE-2018-2613.json
	modified:   2018/2xxx/CVE-2018-2614.json
	modified:   2018/2xxx/CVE-2018-2615.json
	modified:   2018/2xxx/CVE-2018-2616.json
	modified:   2018/2xxx/CVE-2018-2617.json
	modified:   2018/2xxx/CVE-2018-2618.json
	modified:   2018/2xxx/CVE-2018-2619.json
	modified:   2018/2xxx/CVE-2018-2620.json
	modified:   2018/2xxx/CVE-2018-2621.json
	modified:   2018/2xxx/CVE-2018-2622.json
	modified:   2018/2xxx/CVE-2018-2623.json
	modified:   2018/2xxx/CVE-2018-2624.json
	modified:   2018/2xxx/CVE-2018-2625.json
	modified:   2018/2xxx/CVE-2018-2626.json
	modified:   2018/2xxx/CVE-2018-2627.json
	modified:   2018/2xxx/CVE-2018-2629.json
	modified:   2018/2xxx/CVE-2018-2630.json
	modified:   2018/2xxx/CVE-2018-2631.json
	modified:   2018/2xxx/CVE-2018-2632.json
	modified:   2018/2xxx/CVE-2018-2633.json
	modified:   2018/2xxx/CVE-2018-2634.json
	modified:   2018/2xxx/CVE-2018-2635.json
	modified:   2018/2xxx/CVE-2018-2636.json
	modified:   2018/2xxx/CVE-2018-2637.json
	modified:   2018/2xxx/CVE-2018-2638.json
	modified:   2018/2xxx/CVE-2018-2639.json
	modified:   2018/2xxx/CVE-2018-2640.json
	modified:   2018/2xxx/CVE-2018-2641.json
	modified:   2018/2xxx/CVE-2018-2642.json
	modified:   2018/2xxx/CVE-2018-2643.json
	modified:   2018/2xxx/CVE-2018-2644.json
	modified:   2018/2xxx/CVE-2018-2645.json
	modified:   2018/2xxx/CVE-2018-2646.json
	modified:   2018/2xxx/CVE-2018-2647.json
	modified:   2018/2xxx/CVE-2018-2648.json
	modified:   2018/2xxx/CVE-2018-2649.json
	modified:   2018/2xxx/CVE-2018-2650.json
	modified:   2018/2xxx/CVE-2018-2651.json
	modified:   2018/2xxx/CVE-2018-2652.json
	modified:   2018/2xxx/CVE-2018-2653.json
	modified:   2018/2xxx/CVE-2018-2654.json
	modified:   2018/2xxx/CVE-2018-2655.json
	modified:   2018/2xxx/CVE-2018-2656.json
	modified:   2018/2xxx/CVE-2018-2657.json
	modified:   2018/2xxx/CVE-2018-2658.json
	modified:   2018/2xxx/CVE-2018-2659.json
	modified:   2018/2xxx/CVE-2018-2660.json
	modified:   2018/2xxx/CVE-2018-2661.json
	modified:   2018/2xxx/CVE-2018-2662.json
	modified:   2018/2xxx/CVE-2018-2663.json
	modified:   2018/2xxx/CVE-2018-2664.json
	modified:   2018/2xxx/CVE-2018-2665.json
	modified:   2018/2xxx/CVE-2018-2666.json
	modified:   2018/2xxx/CVE-2018-2667.json
	modified:   2018/2xxx/CVE-2018-2668.json
	modified:   2018/2xxx/CVE-2018-2669.json
	modified:   2018/2xxx/CVE-2018-2670.json
	modified:   2018/2xxx/CVE-2018-2671.json
	modified:   2018/2xxx/CVE-2018-2672.json
	modified:   2018/2xxx/CVE-2018-2673.json
	modified:   2018/2xxx/CVE-2018-2674.json
	modified:   2018/2xxx/CVE-2018-2675.json
	modified:   2018/2xxx/CVE-2018-2676.json
	modified:   2018/2xxx/CVE-2018-2677.json
	modified:   2018/2xxx/CVE-2018-2678.json
	modified:   2018/2xxx/CVE-2018-2679.json
	modified:   2018/2xxx/CVE-2018-2680.json
	modified:   2018/2xxx/CVE-2018-2681.json
	modified:   2018/2xxx/CVE-2018-2682.json
	modified:   2018/2xxx/CVE-2018-2683.json
	modified:   2018/2xxx/CVE-2018-2684.json
	modified:   2018/2xxx/CVE-2018-2685.json
	modified:   2018/2xxx/CVE-2018-2686.json
	modified:   2018/2xxx/CVE-2018-2687.json
	modified:   2018/2xxx/CVE-2018-2688.json
	modified:   2018/2xxx/CVE-2018-2689.json
	modified:   2018/2xxx/CVE-2018-2690.json
	modified:   2018/2xxx/CVE-2018-2691.json
	modified:   2018/2xxx/CVE-2018-2692.json
	modified:   2018/2xxx/CVE-2018-2693.json
	modified:   2018/2xxx/CVE-2018-2694.json
	modified:   2018/2xxx/CVE-2018-2695.json
	modified:   2018/2xxx/CVE-2018-2696.json
	modified:   2018/2xxx/CVE-2018-2697.json
	modified:   2018/2xxx/CVE-2018-2698.json
	modified:   2018/2xxx/CVE-2018-2699.json
	modified:   2018/2xxx/CVE-2018-2700.json
	modified:   2018/2xxx/CVE-2018-2701.json
	modified:   2018/2xxx/CVE-2018-2702.json
	modified:   2018/2xxx/CVE-2018-2703.json
	modified:   2018/2xxx/CVE-2018-2704.json
	modified:   2018/2xxx/CVE-2018-2705.json
	modified:   2018/2xxx/CVE-2018-2706.json
	modified:   2018/2xxx/CVE-2018-2707.json
	modified:   2018/2xxx/CVE-2018-2708.json
	modified:   2018/2xxx/CVE-2018-2709.json
	modified:   2018/2xxx/CVE-2018-2710.json
	modified:   2018/2xxx/CVE-2018-2711.json
	modified:   2018/2xxx/CVE-2018-2712.json
	modified:   2018/2xxx/CVE-2018-2713.json
	modified:   2018/2xxx/CVE-2018-2714.json
	modified:   2018/2xxx/CVE-2018-2715.json
	modified:   2018/2xxx/CVE-2018-2716.json
	modified:   2018/2xxx/CVE-2018-2717.json
	modified:   2018/2xxx/CVE-2018-2719.json
	modified:   2018/2xxx/CVE-2018-2720.json
	modified:   2018/2xxx/CVE-2018-2721.json
	modified:   2018/2xxx/CVE-2018-2722.json
	modified:   2018/2xxx/CVE-2018-2723.json
	modified:   2018/2xxx/CVE-2018-2724.json
	modified:   2018/2xxx/CVE-2018-2725.json
	modified:   2018/2xxx/CVE-2018-2726.json
	modified:   2018/2xxx/CVE-2018-2727.json
	modified:   2018/2xxx/CVE-2018-2728.json
	modified:   2018/2xxx/CVE-2018-2729.json
	modified:   2018/2xxx/CVE-2018-2730.json
	modified:   2018/2xxx/CVE-2018-2731.json
	modified:   2018/2xxx/CVE-2018-2732.json
	modified:   2018/2xxx/CVE-2018-2733.json
2018-01-16 15:22:32 -08:00

144 lines
5.7 KiB
JSON

{
"CVE_data_meta":{
"ASSIGNER":"openssl-security@openssl.org",
"DATE_PUBLIC":"2017-01-26",
"ID":"CVE-2017-3731",
"STATE":"PUBLIC",
"TITLE":"Truncated packet could crash via OOB read"
},
"affects":{
"vendor":{
"vendor_data":[
{
"product":{
"product_data":[
{
"product_name":"OpenSSL",
"version":{
"version_data":[
{
"version_value":"openssl-1.1.0"
},
{
"version_value":"openssl-1.1.0a"
},
{
"version_value":"openssl-1.1.0b"
},
{
"version_value":"openssl-1.1.0c"
},
{
"version_value":"openssl-1.0.2"
},
{
"version_value":"openssl-1.0.2a"
},
{
"version_value":"openssl-1.0.2b"
},
{
"version_value":"openssl-1.0.2c"
},
{
"version_value":"openssl-1.0.2d"
},
{
"version_value":"openssl-1.0.2e"
},
{
"version_value":"openssl-1.0.2f"
},
{
"version_value":"openssl-1.0.2g"
},
{
"version_value":"openssl-1.0.2h"
},
{
"version_value":"openssl-1.0.2i"
},
{
"version_value":"openssl-1.0.2j"
}
]
}
}
]
},
"vendor_name":"OpenSSL"
}
]
}
},
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"out-of-bounds read"
}
]
}
]
},
"references":{
"reference_data":[
{
"url":"https://www.openssl.org/news/secadv/20170126.txt"
},
{
"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html"
},
{
"url":"http://securityadvisories.paloaltonetworks.com/Home/Detail/82"
},
{
"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html"
},
{
"url":"https://www.tenable.com/security/tns-2017-04"
},
{
"url":"https://security.netapp.com/advisory/ntap-20171019-0002/"
},
{
"url":"https://source.android.com/security/bulletin/pixel/2017-11-01"
},
{
"url":"http://www.debian.org/security/2017/dsa-3773"
},
{
"url":"https://security.FreeBSD.org/advisories/FreeBSD-SA-17:02.openssl.asc"
},
{
"url":"https://security.gentoo.org/glsa/201702-07"
},
{
"url":"http://rhn.redhat.com/errata/RHSA-2017-0286.html"
},
{
"url":"http://www.securityfocus.com/bid/95813"
},
{
"url":"http://www.securitytracker.com/id/1037717"
},
{
"url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html"
}
]
}
}