Candidate: CVE-2017-3733 PublicDate: 2017-05-04 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3733 https://www.openssl.org/news/secadv/20170216.txt Description: During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected. Ubuntu-Description: Notes: mdeslaur> only affects 1.1.x Bugs: Priority: high Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_openssl: upstream_openssl: needs-triage precise_openssl: not-affected (1.0.1-4ubuntu5.39) trusty_openssl: not-affected (1.0.1f-1ubuntu2.22) trusty/esm_openssl: not-affected (1.0.1f-1ubuntu2.22) vivid/ubuntu-core_openssl: not-affected vivid/stable-phone-overlay_openssl: not-affected xenial_openssl: not-affected (1.0.2g-1ubuntu4.6) esm-infra/xenial_openssl: not-affected (1.0.2g-1ubuntu4.6) yakkety_openssl: not-affected (1.0.2g-1ubuntu9.1) devel_openssl: not-affected (1.0.2g-1ubuntu11) Patches_openssl098: upstream_openssl098: needs-triage precise_openssl098: not-affected trusty_openssl098: not-affected trusty/esm_openssl098: DNE (trusty was not-affected) vivid/ubuntu-core_openssl098: DNE vivid/stable-phone-overlay_openssl098: DNE xenial_openssl098: DNE yakkety_openssl098: DNE devel_openssl098: DNE