CVE-2017-3730

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
opensslCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
opensslopenssl
1.1.0
opensslopenssl
1.1.0a:a
opensslopenssl
1.1.0b:b
opensslopenssl
1.1.0c:c
oracleagile_engineering_data_management
6.1.3
oracleagile_engineering_data_management
6.2.0
oraclecommunications_application_session_controller
3.7.1
oraclecommunications_application_session_controller
3.8.0
oraclecommunications_eagle_lnp_application_processor
10.0
oraclecommunications_eagle_lnp_application_processor
10.1
oraclecommunications_eagle_lnp_application_processor
10.2
oraclecommunications_operations_monitor
3.4
oraclecommunications_operations_monitor
4.0
oraclejd_edwards_enterpriseone_tools
9.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssl
bullseye
1.1.1w-0+deb11u1
fixed
jessie
not-affected
wheezy
not-affected
bullseye (security)
1.1.1w-0+deb11u2
fixed
bookworm
3.0.14-1~deb12u1
fixed
bookworm (security)
3.0.14-1~deb12u2
fixed
sid
3.3.2-2
fixed
trixie
3.3.2-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssl
yakkety
not-affected
xenial
not-affected
trusty
not-affected
precise
not-affected
openssl098
yakkety
dne
xenial
dne
trusty
dne
precise
not-affected