[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-2097Date: (C)2022-07-06   (M)2024-04-26


AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.3CVSS Score : 5.0
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 1.4Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: LOWAvailability: NONE
Integrity: NONE 
Availability: NONE 
  
Reference:
DSA-5343
FEDORA-2022-3fdc2d3047
FEDORA-2022-41890e9e44
FEDORA-2022-89a17be281
GLSA-202210-02
https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html
https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93
https://security.netapp.com/advisory/ntap-20220715-0011/
https://security.netapp.com/advisory/ntap-20230420-0008/
https://www.openssl.org/news/secadv/20220705.txt

CPE    1
cpe:/a:openssl:openssl
CWE    1
CWE-327
OVAL    35
oval:org.secpod.oval:def:86478
oval:org.secpod.oval:def:2107913
oval:org.secpod.oval:def:89046757
oval:org.secpod.oval:def:89047561
...

© SecPod Technologies