Cryptographic Issues Affecting openssl package, versions >=1.0.0, <1.0.108
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-COCOAPODS-OPENSSL-470986
- published 2 Oct 2019
- disclosed 20 Dec 2014
- credit Unknown
Introduced: 20 Dec 2014
CVE-2014-8275 Open this link in a new tabHow to fix?
Upgrade OpenSSL
to version 1.0.108 or higher.
Overview
OpenSSL is a SSL/TLS and Crypto toolkit. Deprecated in Mac OS and gone in iOS, this spec gives your project non-deprecated OpenSSL support.
Affected versions of this package are vulnerable to Cryptographic Issues. OpenSSL is vulnerable to protection mechanism bypass. This is because OpenSSL accepts several variations of certificate signature algorithms and signature encodings. It doesn't then enforce a match between the signature algorithm between the signed and unsigned portions of the certificate. This only affects custom applications which rely on the uniqueness of the fingerprint.
References
- Apple Security Advisory
- Apple Security Announcement
- Debian Security Advisory
- Fedora Security Announcement
- GitHub Commit
- GitHub Commit
- GitHub Comparison
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- HP Security Bulletin
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10679
- https://bto.bluecoat.com/security-advisory/sa88
- https://kc.mcafee.com/corporate/index?page=content&id=SB10102
- https://kc.mcafee.com/corporate/index?page=content&id=SB10108
- https://support.citrix.com/article/CTX216642
- https://www.openssl.org/news/secadv_20150108.txt
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150310-ssl
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- Oracle Security Advisory
- Oracle Security Advisory
- Oracle Security Bulletin
- Oracle Security Bulletin
- Oracle Security Bulletin
- Oracle Security Bulletin
- RedHat Security Advisory
- RedHat Security Advisory
- Security Focus
- Security Tracker