CVE-2010-1633
Summary
| CVE | CVE-2010-1633 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-03 14:30:00 UTC |
| Updated | 2023-11-07 02:05:00 UTC |
| Description | RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x before 1.0.0a, as used by pkeyutl and possibly other applications, returns uninitialized memory upon failure, which might allow context-dependent attackers to bypass intended key requirements or obtain sensitive information via unspecified vectors. NOTE: some of these details are obtained from third party information. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Advisory SA57353 - IBM Storage System DS8870 OpenSSL Multiple Vulnerabilities - Secunia |
SECUNIA |
secunia.com |
|
| IBM Security Bulletin: Storage HMC OpenSSL upgrade to address cryptographic vulnerabilities. - United States |
CONFIRM |
www-01.ibm.com |
|
| cvs.openssl.org/filediff |
CONFIRM |
cvs.openssl.org |
|
| cvs.openssl.org/chngview |
CONFIRM |
cvs.openssl.org |
|
| OpenSSL Two Vulnerabilities - Advisories - Community |
SECUNIA |
secunia.com |
Vendor Advisory |
| www.openssl.org/news/secadv_20100601.txt |
CONFIRM |
www.openssl.org |
|
| OpenSSL 'EVP_PKEY_verify_recover()' Invalid Return Value Security Bypass Vulnerability |
BID |
www.securityfocus.com |
|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
Patch, Vendor Advisory |
| Bug 598732 – CVE-2010-1633 openssl: information leak due to invalid Return value check |
CONFIRM |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 390284 Oracle Managed Virtualization (VM) Server for x86 Security Update for Open Secure Sockets Layer (OpenSSL) (OVMSA-2023-0013)