Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack
The package openssl098e is provided purely for binary compatibility with older Amazon Linux versions. It does not receive security updates.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | edk2 | 2024-03-13 20:26 | ALAS2-2024-2502 |
Amazon Linux 2 - Core | edk2 | 2024-02-29 10:03 | ALAS2-2024-2483 |
Amazon Linux 2 - Core | openssl | 2024-02-29 10:03 | ALAS2-2024-2479 |
Amazon Linux 2023 | openssl | 2024-02-15 02:51 | ALAS2023-2024-520 |
Amazon Linux 2 - Openssl-snapsafe Extra | openssl-snapsafe | 2024-02-29 00:57 | ALAS2OPENSSL-SNAPSAFE-2024-005 |
Amazon Linux 2 - Core | openssl11 | 2024-02-29 10:03 | ALAS2-2024-2478 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
NVD | CVSSv3 | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |