CVE-2017-3735
CVE-2017-3735 Vulnerability Analysis & Exploit Intelligence
While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
Published Updated Sources: cvelistV5, openssl
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
21%
chance of exploitation in 30 days
CVSS base
Unscored
no source published a base score
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
References
25 on the record
- www.securitytracker.com/id/1039726
vdb-entry
- usn.ubuntu.com/3611-2/
vendor-advisory
- www.debian.org/security/2017/dsa-4018
vendor-advisory
- security.gentoo.org/glsa/201712-03
vendor-advisory
- lists.debian.org/debian-lts-announce/2017/11/msg00011.html
mailing-list
- access.redhat.com/errata/RHSA-2018:3505
vendor-advisory
- www.debian.org/security/2017/dsa-4017
vendor-advisory
- access.redhat.com/errata/RHSA-2018:3221
vendor-advisory
Elsewhere on this site
- openssl software foundationevery CVE for this vendor
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.