Vulnerabilities |
6 via 12 paths |
---|---|
Dependencies |
11 |
Source |
Docker |
Target OS |
alpine:3.4.6 |
high severity
- Vulnerable module: openssl/libcrypto1.0
- Introduced through: openssl/libcrypto1.0@1.0.2n-r0 and openssl/libssl1.0@1.0.2n-r0
- Fixed in: 1.0.2o-r1
Detailed paths
-
Introduced through: alpine@3.4 › openssl/libcrypto1.0@1.0.2n-r0
-
Introduced through: alpine@3.4 › openssl/libssl1.0@1.0.2n-r0
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl
package and not the openssl
package as distributed by Alpine
.
See How to fix?
for Alpine:3.4
relevant fixed versions and status.
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).
Remediation
Upgrade Alpine:3.4
openssl
to version 1.0.2o-r1 or higher.
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-419820.pdf
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=3984ef0b72831da8b3ece4745cac4f8575b19098
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ea7abeeabf92b7aca160bdd0208636d4da69f4f4
- https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/
- https://securityadvisories.paloaltonetworks.com/Home/Detail/133
- https://www.tenable.com/security/tns-2018-12
- https://www.tenable.com/security/tns-2018-13
- https://www.tenable.com/security/tns-2018-14
- https://www.tenable.com/security/tns-2018-17
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0732
- https://www.debian.org/security/2018/dsa-4348
- https://www.debian.org/security/2018/dsa-4355
- https://lists.debian.org/debian-lts-announce/2018/07/msg00043.html
- https://security-tracker.debian.org/tracker/CVE-2018-0732
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
- https://security.gentoo.org/glsa/201811-03
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://security.netapp.com/advisory/ntap-20181105-0001/
- https://security.netapp.com/advisory/ntap-20190118-0002/
- https://www.openssl.org/news/secadv/20180612.txt
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://access.redhat.com/errata/RHSA-2019:1543
- https://access.redhat.com/errata/RHSA-2018:2552
- https://access.redhat.com/errata/RHSA-2018:2553
- https://access.redhat.com/errata/RHSA-2018:3221
- https://access.redhat.com/errata/RHSA-2018:3505
- https://access.redhat.com/errata/RHSA-2019:1296
- https://access.redhat.com/errata/RHSA-2019:1297
- http://www.securityfocus.com/bid/104442
- http://www.securitytracker.com/id/1041090
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2018-0732
- https://usn.ubuntu.com/3692-1/
- https://usn.ubuntu.com/3692-2/
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3984ef0b72831da8b3ece4745cac4f8575b19098
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ea7abeeabf92b7aca160bdd0208636d4da69f4f4
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
medium severity
- Vulnerable module: openssl/libcrypto1.0
- Introduced through: openssl/libcrypto1.0@1.0.2n-r0 and openssl/libssl1.0@1.0.2n-r0
- Fixed in: 1.0.2o-r0
Detailed paths
-
Introduced through: alpine@3.4 › openssl/libcrypto1.0@1.0.2n-r0
-
Introduced through: alpine@3.4 › openssl/libssl1.0@1.0.2n-r0
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl
package and not the openssl
package as distributed by Alpine
.
See How to fix?
for Alpine:3.4
relevant fixed versions and status.
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).
Remediation
Upgrade Alpine:3.4
openssl
to version 1.0.2o-r0 or higher.
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2ac4c6f7b2b2af20c0e2b0ba05367e454cd11b33
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9310d45087ae546e27e61ddf8f6367f29848220d
- https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/
- https://securityadvisories.paloaltonetworks.com/Home/Detail/133
- https://www.tenable.com/security/tns-2018-04
- https://www.tenable.com/security/tns-2018-06
- https://www.tenable.com/security/tns-2018-07
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0739
- https://www.debian.org/security/2018/dsa-4157
- https://www.debian.org/security/2018/dsa-4158
- https://lists.debian.org/debian-lts-announce/2018/03/msg00033.html
- https://security-tracker.debian.org/tracker/CVE-2018-0739
- https://security.gentoo.org/glsa/202007-53
- https://security.gentoo.org/glsa/201811-21
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://security.netapp.com/advisory/ntap-20180330-0002/
- https://security.netapp.com/advisory/ntap-20180726-0002/
- https://www.openssl.org/news/secadv/20180327.txt
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://access.redhat.com/errata/RHSA-2019:1711
- https://access.redhat.com/errata/RHSA-2019:1712
- https://access.redhat.com/errata/RHSA-2018:3090
- https://access.redhat.com/errata/RHSA-2018:3221
- https://access.redhat.com/errata/RHSA-2018:3505
- https://access.redhat.com/errata/RHSA-2019:0366
- https://access.redhat.com/errata/RHSA-2019:0367
- http://www.securityfocus.com/bid/103518
- http://www.securityfocus.com/bid/105609
- http://www.securitytracker.com/id/1040576
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2018-0739
- https://usn.ubuntu.com/3611-1/
- https://usn.ubuntu.com/3611-2/
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2ac4c6f7b2b2af20c0e2b0ba05367e454cd11b33
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9310d45087ae546e27e61ddf8f6367f29848220d
medium severity
- Vulnerable module: openssl/libcrypto1.0
- Introduced through: openssl/libcrypto1.0@1.0.2n-r0 and openssl/libssl1.0@1.0.2n-r0
- Fixed in: 1.0.2o-r0
Detailed paths
-
Introduced through: alpine@3.4 › openssl/libcrypto1.0@1.0.2n-r0
-
Introduced through: alpine@3.4 › openssl/libssl1.0@1.0.2n-r0
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl
package and not the openssl
package as distributed by Alpine
.
See How to fix?
for Alpine:3.4
relevant fixed versions and status.
Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).
Remediation
Upgrade Alpine:3.4
openssl
to version 1.0.2o-r0 or higher.
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=56d5a4bfcaf37fa420aef2bb881aa55e61cf5f2f
- https://www.tenable.com/security/tns-2018-04
- https://www.tenable.com/security/tns-2018-06
- https://www.tenable.com/security/tns-2018-07
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0733
- https://security-tracker.debian.org/tracker/CVE-2018-0733
- https://security.gentoo.org/glsa/201811-21
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://security.netapp.com/advisory/ntap-20180330-0002/
- https://www.openssl.org/news/secadv/20180327.txt
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/103517
- http://www.securitytracker.com/id/1040576
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=56d5a4bfcaf37fa420aef2bb881aa55e61cf5f2f
medium severity
- Vulnerable module: openssl/libcrypto1.0
- Introduced through: openssl/libcrypto1.0@1.0.2n-r0 and openssl/libssl1.0@1.0.2n-r0
- Fixed in: 1.0.2q-r0
Detailed paths
-
Introduced through: alpine@3.4 › openssl/libcrypto1.0@1.0.2n-r0
-
Introduced through: alpine@3.4 › openssl/libssl1.0@1.0.2n-r0
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl
package and not the openssl
package as distributed by Alpine
.
See How to fix?
for Alpine:3.4
relevant fixed versions and status.
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
Remediation
Upgrade Alpine:3.4
openssl
to version 1.0.2q-r0 or higher.
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=43e6a58d4991a451daf4891ff05a48735df871ac
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8abfe72e8c1de1b95f50aa0d9134803b4d00070f
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ef11e19d1365eea2b1851e6f540a0bf365d303e7
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/
- https://www.tenable.com/security/tns-2018-16
- https://www.tenable.com/security/tns-2018-17
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0734
- https://www.debian.org/security/2018/dsa-4348
- https://www.debian.org/security/2018/dsa-4355
- https://security-tracker.debian.org/tracker/CVE-2018-0734
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://security.netapp.com/advisory/ntap-20181105-0002/
- https://security.netapp.com/advisory/ntap-20190118-0002/
- https://security.netapp.com/advisory/ntap-20190423-0002/
- https://www.openssl.org/news/secadv/20181030.txt
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00030.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://access.redhat.com/errata/RHSA-2019:2304
- https://access.redhat.com/errata/RHSA-2019:3700
- https://access.redhat.com/errata/RHSA-2019:3932
- https://access.redhat.com/errata/RHSA-2019:3933
- https://access.redhat.com/errata/RHSA-2019:3935
- http://www.securityfocus.com/bid/105758
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00056.html
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2018-0734
- https://usn.ubuntu.com/3840-1/
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=43e6a58d4991a451daf4891ff05a48735df871ac
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=8abfe72e8c1de1b95f50aa0d9134803b4d00070f
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=ef11e19d1365eea2b1851e6f540a0bf365d303e7
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
medium severity
- Vulnerable module: openssl/libcrypto1.0
- Introduced through: openssl/libcrypto1.0@1.0.2n-r0 and openssl/libssl1.0@1.0.2n-r0
- Fixed in: 1.0.2o-r2
Detailed paths
-
Introduced through: alpine@3.4 › openssl/libcrypto1.0@1.0.2n-r0
-
Introduced through: alpine@3.4 › openssl/libssl1.0@1.0.2n-r0
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl
package and not the openssl
package as distributed by Alpine
.
See How to fix?
for Alpine:3.4
relevant fixed versions and status.
The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o).
Remediation
Upgrade Alpine:3.4
openssl
to version 1.0.2o-r2 or higher.
References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=349a41da1ad88ad87825414752a8ff5fdd6a6c3f
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=6939eab03a6e23d2bd2c3f5e34fe1d48e542e787
- https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/
- https://securityadvisories.paloaltonetworks.com/Home/Detail/133
- https://www.tenable.com/security/tns-2018-12
- https://www.tenable.com/security/tns-2018-13
- https://www.tenable.com/security/tns-2018-14
- https://www.tenable.com/security/tns-2018-17
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0737
- https://www.debian.org/security/2018/dsa-4348
- https://www.debian.org/security/2018/dsa-4355
- https://lists.debian.org/debian-lts-announce/2018/07/msg00043.html
- https://security-tracker.debian.org/tracker/CVE-2018-0737
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
- https://security.gentoo.org/glsa/201811-21
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://security.netapp.com/advisory/ntap-20180726-0003/
- https://www.openssl.org/news/secadv/20180416.txt
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://access.redhat.com/errata/RHSA-2019:3932
- https://access.redhat.com/errata/RHSA-2019:3933
- https://access.redhat.com/errata/RHSA-2019:3935
- https://access.redhat.com/errata/RHSA-2018:3221
- https://access.redhat.com/errata/RHSA-2018:3505
- http://www.securityfocus.com/bid/103766
- http://www.securitytracker.com/id/1040685
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2018-0737
- https://usn.ubuntu.com/3628-1/
- https://usn.ubuntu.com/3628-2/
- https://usn.ubuntu.com/3692-1/
- https://usn.ubuntu.com/3692-2/
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=349a41da1ad88ad87825414752a8ff5fdd6a6c3f
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=6939eab03a6e23d2bd2c3f5e34fe1d48e542e787
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EWC42UXL5GHTU5G77VKBF6JYUUNGSHOM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3IVFGSERAZLNJCK35TEM2R4726XIH3Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBEV5QGDRFUZDMNECFXUSN5FMYOZDE4V/
medium severity
- Vulnerable module: openssl/libcrypto1.0
- Introduced through: openssl/libcrypto1.0@1.0.2n-r0 and openssl/libssl1.0@1.0.2n-r0
- Fixed in: 1.0.2q-r0
Detailed paths
-
Introduced through: alpine@3.4 › openssl/libcrypto1.0@1.0.2n-r0
-
Introduced through: alpine@3.4 › openssl/libssl1.0@1.0.2n-r0
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssl
package and not the openssl
package as distributed by Alpine
.
See How to fix?
for Alpine:3.4
relevant fixed versions and status.
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Remediation
Upgrade Alpine:3.4
openssl
to version 1.0.2q-r0 or higher.
References
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/
- https://support.f5.com/csp/article/K49711130?utm_source=f5support&utm_medium=RSS
- https://www.tenable.com/security/tns-2018-16
- https://www.tenable.com/security/tns-2018-17
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5407
- https://www.debian.org/security/2018/dsa-4348
- https://www.debian.org/security/2018/dsa-4355
- https://lists.debian.org/debian-lts-announce/2018/11/msg00024.html
- https://security-tracker.debian.org/tracker/CVE-2018-5407
- https://www.exploit-db.com/exploits/45785/
- https://security.gentoo.org/glsa/201903-10
- https://eprint.iacr.org/2018/1060.pdf
- https://github.com/bbbrumley/portsmash
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://security.netapp.com/advisory/ntap-20181126-0001/
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://access.redhat.com/errata/RHSA-2019:2125
- https://access.redhat.com/errata/RHSA-2019:3929
- https://access.redhat.com/errata/RHSA-2019:3931
- https://access.redhat.com/errata/RHSA-2019:3932
- https://access.redhat.com/errata/RHSA-2019:3933
- https://access.redhat.com/errata/RHSA-2019:3935
- https://access.redhat.com/errata/RHSA-2019:0483
- https://access.redhat.com/errata/RHSA-2019:0651
- https://access.redhat.com/errata/RHSA-2019:0652
- http://www.securityfocus.com/bid/105897
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2018-5407
- https://usn.ubuntu.com/3840-1/
- https://support.f5.com/csp/article/K49711130?utm_source=f5support&%3Butm_medium=RSS
- https://www.exploit-db.com/exploits/45785