[FREEBSD:A28E8B7E-FC70-11EC-856E-D4C9EF517024] OpenSSL -- AES OCB fails to encrypt some bytes

Severity Medium
Affected Packages 2
CVEs 1

The OpenSSL project reports:

  AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised
    implementation will not encrypt the entirety of the data under some
    circumstances.  This could reveal sixteen bytes of data that was
    preexisting in the memory that wasn't written.  In the special case of
    "in place" encryption, sixteen bytes of the plaintext would be revealed.
Package Affected Version
pkg:freebsd/openssl-devel < 3.0.5
pkg:freebsd/openssl < 1.1.1q,1
Source # ID Name URL
FreeBSD VuXML https://www.openssl.org/news/secadv/20220705.txt
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/openssl-devel openssl-devel < 3.0.5
Affected pkg:freebsd/openssl openssl < 1.1.1q,1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...