CVE-2024-0727
Public on 2024-01-25
Modified on 2024-05-17
Description
Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack
The package openssl098e is provided purely for binary compatibility with older Amazon Linux versions. It does not receive security updates.
The package openssl098e is provided purely for binary compatibility with older Amazon Linux versions. It does not receive security updates.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | edk2 | 2024-02-29 | ALAS2-2024-2483 | Fixed |
Amazon Linux 2 - Core | edk2 | 2024-03-13 | ALAS2-2024-2502 | Fixed |
Amazon Linux 1 | openssl | No Fix Planned | ||
Amazon Linux 2 - Core | openssl | 2024-02-29 | ALAS2-2024-2479 | Fixed |
Amazon Linux 2023 | openssl | 2024-02-15 | ALAS2023-2024-520 | Fixed |
Amazon Linux 2 - Openssl-snapsafe Extra | openssl-snapsafe | 2024-02-29 | ALAS2OPENSSL-SNAPSAFE-2024-005 | Fixed |
Amazon Linux 2 - Core | openssl098e | No Fix Planned | ||
Amazon Linux 2 - Core | openssl11 | 2024-02-29 | ALAS2-2024-2478 | Fixed |
Amazon Linux 2 - Core | shim | Pending Fix |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
NVD | CVSSv3 | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |