CVE-2017-3735
Last modified
CVE-2017-3735 is a vulnerability of currently unknown severity. While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. EPSS estimates a 17.70% chance of exploitation in the next 30 days.
Description
While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 0.9.7j |
| Openssl | Openssl | 0.9.7k |
| Openssl | Openssl | 0.9.7l |
| Openssl | Openssl | 0.9.7m |
| Openssl | Openssl | 0.9.8 |
| Openssl | Openssl | 0.9.8a |
| Openssl | Openssl | 0.9.8b |
| Openssl | Openssl | 0.9.8c |
| Openssl | Openssl | 0.9.8d |
| Openssl | Openssl | 0.9.8e |
| Openssl | Openssl | 0.9.8f |
| Openssl | Openssl | 0.9.8g |
| Openssl | Openssl | 0.9.8h |
| Openssl | Openssl | 0.9.8i |
| Openssl | Openssl | 0.9.8j |
| Openssl | Openssl | 0.9.8k |
| Openssl | Openssl | 0.9.8l |
| Openssl | Openssl | 0.9.8m |
| Openssl | Openssl | 0.9.8n |
| Openssl | Openssl | 0.9.8o |
| Openssl | Openssl | 0.9.8p |
| Openssl | Openssl | 0.9.8q |
| Openssl | Openssl | 0.9.8r |
| Openssl | Openssl | 0.9.8s |
| Openssl | Openssl | 0.9.8t |
| Openssl | Openssl | 0.9.8u |
| Openssl | Openssl | 0.9.8v |
| Openssl | Openssl | 0.9.8w |
| Openssl | Openssl | 0.9.8x |
| Openssl | Openssl | 0.9.8y |
| Openssl | Openssl | 0.9.8z |
| Openssl | Openssl | 0.9.8za |
| Openssl | Openssl | 0.9.8zb |
| Openssl | Openssl | 0.9.8zc |
| Openssl | Openssl | 0.9.8ze |
| Openssl | Openssl | 0.9.8zg |
| Openssl | Openssl | 1.0.0 |
| Openssl | Openssl | 1.0.0a |
| Openssl | Openssl | 1.0.0b |
| Openssl | Openssl | 1.0.0c |
| Openssl | Openssl | 1.0.0d |
| Openssl | Openssl | 1.0.0e |
| Openssl | Openssl | 1.0.0f |
| Openssl | Openssl | 1.0.0g |
| Openssl | Openssl | 1.0.0h |
| Openssl | Openssl | 1.0.0i |
| Openssl | Openssl | 1.0.0j |
| Openssl | Openssl | 1.0.0k |
| Openssl | Openssl | 1.0.0l |
| Openssl | Openssl | 1.0.0m |
Showing 50 of 90 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/100515Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039726Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20170927-0001/Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171107-0002/Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2017/dsa-4017Third Party Advisory
- https://www.debian.org/security/2017/dsa-4018Third Party Advisory
- https://www.openssl.org/news/secadv/20170828.txtPatch, Vendor Advisory
- https://www.openssl.org/news/secadv/20171102.txtIssue Tracking, Vendor Advisory
- https://www.tenable.com/security/tns-2017-14Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/100515Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039726Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20170927-0001/Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171107-0002/Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2017/dsa-4017Third Party Advisory
- https://www.debian.org/security/2017/dsa-4018Third Party Advisory
- https://www.openssl.org/news/secadv/20170828.txtPatch, Vendor Advisory
- https://www.openssl.org/news/secadv/20171102.txtIssue Tracking, Vendor Advisory
- https://www.tenable.com/security/tns-2017-14Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3735?
How severe is CVE-2017-3735?
How do I fix CVE-2017-3735?
Are you affected by CVE-2017-3735?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
