CVE-2018-0733
Last modified
CVE-2018-0733 is a vulnerability of currently unknown severity. Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. EPSS estimates a 8.61% chance of exploitation in the next 30 days.
Description
Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 1.1.0, <= 1.1.0g |
References
- http://www.securityfocus.com/bid/103517Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040576Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20180330-0002/Third Party Advisory
- https://www.openssl.org/news/secadv/20180327.txtVendor Advisory
- http://www.securityfocus.com/bid/103517Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040576Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20180330-0002/Third Party Advisory
- https://www.openssl.org/news/secadv/20180327.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0733?
How severe is CVE-2018-0733?
How do I fix CVE-2018-0733?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-0724Cross-site scripting (XSS) vulnerability in Q'center Virtual…
- CVE-2018-0728This improper access control vulnerability in Helpdesk allow…7.5
- CVE-2018-0729This command injection vulnerability in Music Station allows…9.8
- CVE-2018-0730This command injection vulnerability in File Station allows …9.8
- CVE-2018-0731Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-0732During key agreement in a TLS handshake using a DH(E) based …7.5
- CVE-2018-0734The OpenSSL DSA signature algorithm has been shown to be vul…5.9
- CVE-2018-0735The OpenSSL ECDSA signature algorithm has been shown to be v…5.9
- CVE-2018-0736Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-0737The OpenSSL RSA Key generation algorithm has been shown to b…
- CVE-2018-0738Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-0739Constructed ASN.1 types with a recursive definition (such as…
Are you affected by CVE-2018-0733?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
