CVE-2018-1000808

Impact:
Low
Public Date:
2017-11-29
CWE:
CWE-400
Bugzilla:
1640216: CVE-2018-1000808 pyOpenSSL: Failure to release memory before removing last reference in PKCS #12 Store

The MITRE CVE dictionary describes this issue as:

Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploitable via Depends upon calling application, however it could be as simple as initiating a TLS connection. Anything that would cause the calling application to reload certificates from a PKCS #12 store.. This vulnerability appears to have been fixed in 17.5.0.

Find out more about CVE-2018-1000808 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 3.7
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 13.0 (Queens) pyOpenSSL Affected
Red Hat OpenStack Platform 12.0 pyOpenSSL Affected
Red Hat OpenStack Platform 10 pyOpenSSL Affected
Red Hat Gluster Storage 3 pyOpenSSL Under investigation
Red Hat Enterprise Linux 7 pyOpenSSL Affected
Red Hat Enterprise Linux 6 pyOpenSSL Will not fix
Red Hat Enterprise Linux 5 pyOpenSSL Under investigation
RHEV Manager 3 pyOpenSSL Will not fix

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.