CVE-2011-4577

UnknownEPSS 9.33%

Last modified

CVE-2011-4577 is a vulnerability of currently unknown severity. OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.. EPSS estimates a 9.33% chance of exploitation in the next 30 days.

Description

OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.

Metrics

EPSS Probability
9.33%

94.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpensslOpenssl<= 0.9.8r
OpensslOpenssl0.9.1c
OpensslOpenssl0.9.2b
OpensslOpenssl0.9.4
OpensslOpenssl0.9.5
OpensslOpenssl0.9.5a
OpensslOpenssl0.9.6
OpensslOpenssl0.9.6a
OpensslOpenssl0.9.6b
OpensslOpenssl0.9.6c
OpensslOpenssl0.9.6d
OpensslOpenssl0.9.6e
OpensslOpenssl0.9.6f
OpensslOpenssl0.9.6g
OpensslOpenssl0.9.6h
OpensslOpenssl0.9.6i
OpensslOpenssl0.9.6j
OpensslOpenssl0.9.6k
OpensslOpenssl0.9.6l
OpensslOpenssl0.9.6m
OpensslOpenssl0.9.7
OpensslOpenssl0.9.7a
OpensslOpenssl0.9.7b
OpensslOpenssl0.9.7c
OpensslOpenssl0.9.7d
OpensslOpenssl0.9.7e
OpensslOpenssl0.9.7f
OpensslOpenssl0.9.7g
OpensslOpenssl0.9.7h
OpensslOpenssl0.9.7i
OpensslOpenssl0.9.7j
OpensslOpenssl0.9.7k
OpensslOpenssl0.9.7l
OpensslOpenssl0.9.7m
OpensslOpenssl0.9.8
OpensslOpenssl0.9.8a
OpensslOpenssl0.9.8b
OpensslOpenssl0.9.8c
OpensslOpenssl0.9.8d
OpensslOpenssl0.9.8e
OpensslOpenssl0.9.8f
OpensslOpenssl0.9.8g
OpensslOpenssl0.9.8h
OpensslOpenssl0.9.8i
OpensslOpenssl0.9.8j
OpensslOpenssl0.9.8k
OpensslOpenssl0.9.8l
OpensslOpenssl0.9.8m
OpensslOpenssl0.9.8n
OpensslOpenssl0.9.8o

Showing 50 of 58 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-4577?
OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.
How severe is CVE-2011-4577?
Severity scoring for CVE-2011-4577 is pending analysis. The EPSS model estimates a 9.33% probability of exploitation in the next 30 days.
How do I fix CVE-2011-4577?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-4577?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST