OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability
BID:49469
Info
OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability
| Bugtraq ID: | 49469 |
| Class: | Design Error |
| CVE: |
CVE-2011-3207 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2011 12:00AM |
| Updated: | Apr 13 2015 09:49PM |
| Credit: | Kaspar Brand |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6 OpenSSL Project OpenSSL 1.0.0d OpenSSL Project OpenSSL 1.0.0c OpenSSL Project OpenSSL 1.0.0b OpenSSL Project OpenSSL 1.0.0a Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Kolab Kolab Groupware Server 2.2.4 Kolab Kolab Groupware Server 2.3.2 Kolab Kolab Groupware Server 2.3.1 HP System Management Homepage 6.2.2 7 HP System Management Homepage 6.0 .96 HP System Management Homepage 3.0.2 .77 HP System Management Homepage 3.0.1 .73 HP System Management Homepage 3.0 .68 HP System Management Homepage 3.0 .64 HP System Management Homepage 6.3 HP System Management Homepage 6.2.0-12 HP System Management Homepage 6.2 HP System Management Homepage 6.2 HP System Management Homepage 6.1.0.103 HP System Management Homepage 6.1.0.102 HP System Management Homepage 6.1.0-103 HP System Management Homepage 6.1 HP System Management Homepage 6.0.0.95 HP System Management Homepage 6.0.0-95 HP System Management Homepage 6.0 HP System Management Homepage 3.0.2.77 B HP System Management Homepage 3.0.2-77 HP System Management Homepage 3.0.1-73 HP System Management Homepage 3.0.0-68 HP System Management Homepage 0 HP Insight Control for Linux (IC-Linux) 7.0 Avaya Aura Experience Portal 6.0 Avaya 96x1 IP Deskphone 6 Apple Mac Os X 10.7.4 Apple Mac Os X 10.7.3 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 |
| Not Vulnerable: |
OpenSSL Project OpenSSL 1.0.0e Kolab Kolab Groupware Server 2.3.3 HP System Management Homepage 7.0 |
Discussion
OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability
OpenSSL is prone to a security-bypass vulnerability.
A successful exploit will allow attackers to bypass the certificate validation mechanism. This may aid in further attacks.
OpenSSL versions 1.0.0 through 1.0.0d.
OpenSSL is prone to a security-bypass vulnerability.
A successful exploit will allow attackers to bypass the certificate validation mechanism. This may aid in further attacks.
OpenSSL versions 1.0.0 through 1.0.0d.
Exploit / POC
OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.8
Mandriva Linux Mandrake 2010.1 x86_64
Apple Mac OS X 10.6.8
Apple Mac OS X 10.8.3
Apple Mac OS X 10.8.2
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.8
-
Apple OSXUpdCombo10.8.4.dmg
For OS X Mountain Lion v10.8 and v10.8.2
http://www.apple.com/support/downloads/
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva lib64openssl-engines1.0.0-1.0.0a-1.8mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64openssl1.0.0-1.0.0a-1.8mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64openssl1.0.0-devel-1.0.0a-1.8mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64openssl1.0.0-static-devel-1.0.0a-1.8mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva openssl-1.0.0a-1.8mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
Apple Mac OS X 10.6.8
-
Apple SecUpdSrvr2013-002.dmg
For Mac OS X Server v10.6.8
http://www.apple.com/support/downloads/
Apple Mac OS X 10.8.3
-
Apple OSXUpd10.8.4.dmg
For OS X Mountain Lion v10.8.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.8.2
-
Apple OSXUpdCombo10.8.4.dmg
For OS X Mountain Lion v10.8 and v10.8.2
http://www.apple.com/support/downloads/
References
OpenSSL Internal Certificate Verification Routine Security Bypass Vulnerability
References:
References:
- [Kolab-announce] Announcing the Kolab Server 2.3.3 (Kolab)
- IBM Netcool System Service Monitor SSM 4.0 Fix Pack 1 README Netcool/System Serv (IBM)
- IBM Netcool System Service Monitor SSM 4.0 Fix Pack 14 README Netcool/System Ser (IBM)
- OpenSSL Homepage (OpenSSL)
- OpenSSL Security Advisory [6 September 2011] (OpenSSL)
- Security Bulletin: IBM Tivoli Netcool System Service Monitors/Application Servic (IBM)
- Security Bulletin: IBM Tivoli Netcool System Service Monitors/Application Servic (IBM)
- Wind River Linux OpenSSL Security Update (WIND00311488 WIND00311487) (Avaya)
- About the security content of OS X Mountain Lion v10.8.4 and Security Update 201 (APPLE)
- ASA-2011-338 openssl security update (RHSA-2011-1409) (Avaya)
- HMC OpenSSL Upgrade to Address Cryptographic Vulnerabilities (IBM)
- IBM Tivoli Composite Application Manager for Transactions Internet Service Monit (IBM)
- Security Bulletin: IBM Endpoint Manager for Remote Control is affected by multip (IBM)
- Security Bulletin: IBM Sterling Connect:Enterprise for UNIX is affected by multi (IBM)
- Security Bulletin: IBM Sterling Connect:Express for UNIX is affected by multiple (IBM)
- Security Bulletin: IBM Tivoli Composite Application Monitoring for Transactions (IBM)
- Security Bulletin: OpenSSL vulnerability issues for IBM Cloudburst (IBM)
- Security Bulletin: OpenSSL vulnerability issues for IBM Service Delivery Manager (IBM)
- Security Bulletin: Tivoli Endpoint Manager for Remote Control is affected by mul (IBM)
- Security Bulletin: Tivoli Remote Control is affected by multiple OpenSSL vulnera (IBM)
- Storage HMC OpenSSL upgrade to address cryptographic vulnerabilities (IBM)