USN-3475-1
Dashboard / Vulnerabilities / USN-3475-1
USN-3475-1
Summary: openssl vulnerabilities
Details: It was discovered that OpenSSL incorrectly parsed the IPAddressFamily extension in X.509 certificates, resulting in an erroneous display of the certificate in text format. (CVE-2017-3735) It was discovered that OpenSSL incorrectly performed the x86_64 Montgomery squaring procedure. While unlikely, a remote attacker could possibly use this issue to recover private keys. This issue only applied to Ubuntu 16.04 LTS, Ubuntu 16.10 and Ubuntu 17.04. (CVE-2017-3736)
References: https://ubuntu.com/security/notices/USN-3475-1, https://ubuntu.com/security/CVE-2017-3735, https://ubuntu.com/security/CVE-2017-3736
Affected packages
Package
Name: openssl
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
