CVE-2017-3735: Buffer Overflow
If an X.509 certificate has a malformed IPAddressFamily extension, OpenSSL could do a one-byte buffer overread. The most likely result would be an erroneous display of the certificate in text format.
External References:
https://www.openssl.org/news/secadv/20170828.txt
References:
https://github.com/openssl/openssl/pull/4276
Other sources
OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error while parsing an IPAdressFamily extension in an X.509 certificate. An attacker could exploit this vulnerability to trigger an out-of-bounds read, resulting in an incorrect text display of the certificate.
— IBM
OpenSSL. An out-of-bounds read issue existed in X.509 IPAddressFamily parsing. This issue was addressed with improved bounds checking.
While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1:1.0.2k-16.el7 - Upgrade
Upgrade
macOS High Sierrato a version that resolves this vulnerability.Fixed in 10.13.2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u4Fixed in 3.0.18-1~deb12u1Fixed in 3.0.18-1~deb12u2Fixed in 3.5.4-1~deb13u1Fixed in 3.5.4-1~deb13u2Fixed in 3.5.5-1 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.0.2 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.1.0 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u4 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.18-1~deb12u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.18-1~deb12u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.4-1~deb13u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.4-1~deb13u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.5.5-1 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.0.2m - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Fixed in 1.1.0g
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-13887
- CVE-2017-9798
- CVE-2017-13905
- CVE-2017-7172
- CVE-2017-13892
- CVE-2017-7171
- CVE-2017-7151
- CVE-2017-1000254
- CVE-2017-13872
- CVE-2017-15422
- CVE-2017-13883
- CVE-2017-7163
- CVE-2017-7155
- CVE-2017-13878
- CVE-2017-13875
- CVE-2017-7159
- CVE-2017-13848
- CVE-2017-13858
- CVE-2017-13847
- CVE-2017-7162
- CVE-2017-13904
- CVE-2017-5754
- CVE-2017-13862
- CVE-2017-13867
- CVE-2017-7173
- CVE-2017-13876
- CVE-2017-13855
- CVE-2017-13865
- CVE-2017-13868
- CVE-2017-13869
- CVE-2017-7154
- CVE-2017-13871
- CVE-2017-13860
- CVE-2017-3735
- CVE-2017-12837
- CVE-2017-7158
- CVE-2017-13911
- CVE-2017-13886
Frequently Asked Questions
What is the severity of CVE-2017-3735?
CVE-2017-3735 has a severity rating of moderate due to the potential for erroneous display of X.509 certificates.
How do I fix CVE-2017-3735?
To fix CVE-2017-3735, upgrade OpenSSL to version 1:1.0.2k-16.el7 or any version above this if available.
What software is affected by CVE-2017-3735?
CVE-2017-3735 affects various versions of OpenSSL, including 0.9.7 through 1.1.0, and certain products by IBM and Apple.
What impact does CVE-2017-3735 have on systems?
The impact of CVE-2017-3735 is mainly cosmetic, leading to potential misrepresentation of certificates without functional damage.
Is there a workaround for CVE-2017-3735?
There are no official workarounds for CVE-2017-3735 aside from applying the available software updates to mitigate the issue.