QID 330104

Date Published: 2022-06-07

QID 330104: IBM Advanced Interactive eXecutive (AIX) Open Secure Sockets Layer (OpenSSL) Denial of Service (DoS) Vulnerability (openssl_advisory35)

OpenSSL is vulnerable to a denial of service, caused by a flaw in the BN_mod_sqrt() function when parsing certificates.

Affected Platform:
AIX 7.1, 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : - "lslpp -L". It also checks for interim fixes installed using the command "emgr -c" or "instfix -k". The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.

A remote attacker could exploit this vulnerability to cause an infinite loop, and results in a denial of service condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fixes to openssl_advisory35 this vulnerability.

    CVEs related to QID 330104

    Software Advisories
    Advisory ID Software Component Link
    openssl_advisory35 URL Logo aix.software.ibm.com/aix/efixes/security/openssl_advisory35.asc