← All CVEs

CVE-2017-3731

high · 7.5

If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.

7.5
CVSS
57.6%
EPSS (exploit prob.)
99th
EPSS percentile
2017-05-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
opensslopenssl1.1.0a
opensslopenssl1.1.0b
opensslopenssl1.1.0c
opensslopenssl1.0.2
opensslopenssl1.0.2
opensslopenssl1.0.2
opensslopenssl1.0.2
opensslopenssl1.0.2a
opensslopenssl1.0.2b
opensslopenssl1.0.2c
opensslopenssl1.0.2d
opensslopenssl1.0.2e
opensslopenssl1.0.2f
opensslopenssl1.0.2h
opensslopenssl1.0.2i
opensslopenssl1.0.2j
nodejsnode.js>= 4.0.0, <= 4.1.2
nodejsnode.js>= 4.2.0, < 4.7.3
nodejsnode.js>= 5.0.0, <= 5.12.0
nodejsnode.js>= 6.0.0, <= 6.8.1
nodejsnode.js>= 6.9.0, < 6.9.5
nodejsnode.js>= 7.0.0, < 7.5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-3731