CVE-2017-3733
04.05.2017, 19:29
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.Enginsight
Vendor | Product | Version |
---|---|---|
openssl | openssl | 1.1.0 |
openssl | openssl | 1.1.0a:a |
openssl | openssl | 1.1.0b:b |
openssl | openssl | 1.1.0c:c |
openssl | openssl | 1.1.0d:d |
hp | operations_agent | 11.14 |
hp | operations_agent | 11.15 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References