CVE-2018-0733
Summary
| CVE | CVE-2018-0733 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-27 21:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OpenSSL CVE-2018-0733 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| git.openssl.org Git - openssl.git/commitdiff | CONFIRM | git.openssl.org | Patch, Vendor Advisory |
| OpenSSL: Multiple vulnerabilities (GLSA 201811-21) — Gentoo security | GENTOO | security.gentoo.org | |
| CPU July 2018 | CONFIRM | www.oracle.com | |
| March 2018 OpenSSL Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| git.openssl.org Git - openssl.git/commitdiff | git.openssl.org | ||
| www.openssl.org/news/secadv/20180327.txt | CONFIRM | www.openssl.org | Vendor Advisory |
| [R1] Nessus Network Monitor 5.5.0 Fixes One Third-party Vulnerability - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| Oracle Critical Patch Update - January 2019 | CONFIRM | www.oracle.com | |
| Oracle Critical Patch Update - July 2019 | MISC | www.oracle.com | |
| [R1] Industrial Security 1.1.0 Fixes One Third-party Vulnerability - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| OpenSSL Bugs Let Users Deny Service and Bypass Authentication in Certain Cases - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CPU Oct 2018 | CONFIRM | www.oracle.com | |
| [R1] OpenSSL Stand-alone Patch Available for SecurityCenter versions 5.0 or Later - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| Oracle Critical Patch Update Advisory - April 2019 | MISC | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Peter Waltenberg (IBM)
Legacy QID Mappings
- 710214 Gentoo Linux Open Secure Sockets Layer Multiple Vulnerabilities (GLSA 201811-21)