A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
References
Configurations
Configuration 1 (hide)
|
History
26 Jun 2023, 22:16
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:openbsd:openbsd:7.2:*:*:*:*:*:*:* cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:* cpe:2.3:o:openbsd:openbsd:7.3:*:*:*:*:*:*:* |
|
CWE | CWE-415 CWE-416 |
|
References | (MISC) https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.3-relnotes.txt - Release Notes | |
References | (MISC) https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/026_ssl.patch.sig - Patch | |
References | (MISC) https://github.com/libressl/openbsd/commit/1d6680b3682f8caba78c627dee60c76da6e20dd7 - Patch | |
References | (MISC) https://github.com/libressl/openbsd/commit/96094ca8757b95298f49d65c813f303bd514b27b - Patch | |
References | (MISC) https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/004_ssl.patch.sig - Patch | |
References | (MISC) https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.7.3-relnotes.txt - Release Notes | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
16 Jun 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-16 20:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-35784
Mitre link : CVE-2023-35784
CVE.ORG link : CVE-2023-35784
JSON object : View
Products Affected
openbsd
- openbsd
- libressl