mirror of
https://github.com/OMGeeky/advisory-db.git
synced 2026-01-02 17:46:38 +01:00
Add advisory for openssl CVE-2022-2097 (#1277)
This commit is contained in:
23
crates/openssl-src/RUSTSEC-0000-0000.md
Normal file
23
crates/openssl-src/RUSTSEC-0000-0000.md
Normal file
@@ -0,0 +1,23 @@
|
||||
```toml
|
||||
[advisory]
|
||||
id = "RUSTSEC-0000-0000"
|
||||
package = "openssl-src"
|
||||
aliases = ["CVE-2022-2097"]
|
||||
categories = ["crypto-failure"]
|
||||
date = "2022-07-05"
|
||||
url = "https://www.openssl.org/news/secadv/20220705.txt"
|
||||
|
||||
[versions]
|
||||
patched = [">= 111.22, < 300.0", ">= 300.0.9"]
|
||||
```
|
||||
|
||||
# AES OCB fails to encrypt some bytes
|
||||
|
||||
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised
|
||||
implementation will not encrypt the entirety of the data under some
|
||||
circumstances. This could reveal sixteen bytes of data that was
|
||||
preexisting in the memory that wasn't written. In the special case of
|
||||
"in place" encryption, sixteen bytes of the plaintext would be revealed.
|
||||
|
||||
Since OpenSSL does not support OCB based cipher suites for TLS and DTLS,
|
||||
they are both unaffected.
|
||||
Reference in New Issue
Block a user