CVE Database
/

CVE-2018-1000808

Back to search

CVE-2018-1000808

Published: Oct 8, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploitable via Depends upon calling application, however it could be as simple as initiating a TLS connection. Anything that would cause the calling application to reload certificates from a PKCS #12 store.. This vulnerability appears to have been fixed in 17.5.0.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2019:0085
vendor-advisory
x_refsource_REDHAT
USN-3813-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2019:1104
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now