During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
2017-05-04T19:29:00.430
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openssl | openssl | 1.1.0 | Yes |
Application | openssl | openssl | 1.1.0a | Yes |
Application | openssl | openssl | 1.1.0b | Yes |
Application | openssl | openssl | 1.1.0c | Yes |
Application | openssl | openssl | 1.1.0d | Yes |
Application | hp | operations_agent | 11.14 | Yes |
Application | hp | operations_agent | 11.15 | Yes |