CVE-2024-0727
Public on 2024-01-25
Modified on 2024-05-17
Description
Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack
The package openssl098e is provided purely for binary compatibility with older HAQM Linux versions. It does not receive security updates.
The package openssl098e is provided purely for binary compatibility with older HAQM Linux versions. It does not receive security updates.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 2 - Core | edk2 | 2024-02-29 | ALAS2-2024-2483 | Fixed |
HAQM Linux 2 - Core | edk2 | 2024-03-13 | ALAS2-2024-2502 | Fixed |
HAQM Linux 1 | openssl | No Fix Planned | ||
HAQM Linux 2 - Core | openssl | 2024-02-29 | ALAS2-2024-2479 | Fixed |
HAQM Linux 2023 | openssl | 2024-02-15 | ALAS2023-2024-520 | Fixed |
HAQM Linux 2 - Openssl-snapsafe Extra | openssl-snapsafe | 2024-02-29 | ALAS2OPENSSL-SNAPSAFE-2024-005 | Fixed |
HAQM Linux 2 - Core | openssl098e | No Fix Planned | ||
HAQM Linux 2 - Core | openssl11 | 2024-02-29 | ALAS2-2024-2478 | Fixed |
HAQM Linux 2 - Core | shim | Pending Fix |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
NVD | CVSSv3 | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |