USN-6709-1

    Dashboard / Vulnerabilities / USN-6709-1

    USN-6709-1

    Published: 21 Mar 2024Last Modified: 27 Apr 2026

    Summary: openssl1.0 vulnerabilities

    Details: It was discovered that checking excessively long DH keys or parameters may be very slow. A remote attacker could possibly use this issue to cause OpenSSL to consume resources, resulting in a denial of service. (CVE-2023-3446) After the fix for CVE-2023-3446 Bernd Edlinger discovered that a large q parameter value can also trigger an overly long computation during some of these checks. A remote attacker could possibly use this issue to cause OpenSSL to consume resources, resulting in a denial of service. (CVE-2023-3817) David Benjamin discovered that generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. A remote attacker could possibly use this issue to cause OpenSSL to consume resources, resulting in a denial of service. (CVE-2023-5678) Bahaa Naamneh discovered that processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack. (CVE-2024-0727)

    Affected packages

    Package

    Name: openssl1.0

    Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/bionic

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.2n-1ubuntu5.13+esm1

    Affected versions

    1.0.2n-1ubuntu2
    1.0.2n-1ubuntu3
    1.0.2n-1ubuntu4
    1.0.2n-1ubuntu5
    1.0.2n-1ubuntu5.1
    1.0.2n-1ubuntu5.2
    1.0.2n-1ubuntu5.3
    1.0.2n-1ubuntu5.4
    1.0.2n-1ubuntu5.5
    1.0.2n-1ubuntu5.6
    1.0.2n-1ubuntu5.7
    1.0.2n-1ubuntu5.8
    1.0.2n-1ubuntu5.9
    1.0.2n-1ubuntu5.10
    1.0.2n-1ubuntu5.11
    1.0.2n-1ubuntu5.12
    1.0.2n-1ubuntu5.13

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-6709-1 | CVE-DB