{"id":"CVE-2017-3737","details":"OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an \"error state\" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and would immediately fail if you attempted to continue the handshake. This works as designed for the explicit handshake functions (SSL_do_handshake(), SSL_accept() and SSL_connect()), however due to a bug it does not work correctly if SSL_read() or SSL_write() is called directly. In that scenario, if the handshake fails then a fatal error will be returned in the initial function call. If SSL_read()/SSL_write() is subsequently called by the application for the same SSL object then it will succeed and the data is passed without being decrypted/encrypted directly from the SSL/TLS record layer. In order to exploit this issue an application bug would have to be present that resulted in a call to SSL_read()/SSL_write() being issued after having already received a fatal error. OpenSSL version 1.0.2b-1.0.2m are affected. Fixed in OpenSSL 1.0.2n. OpenSSL 1.1.0 is not affected.","modified":"2026-05-18T05:49:34.976930997Z","published":"2017-12-07T16:29:00.193Z","related":["SUSE-FU-2022:0445-1","SUSE-SU-2017:3343-1","openSUSE-SU-2024:11126-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"9.0"}],"source":"CPE_FIELD","vendor_product":"debian:debian_linux"}]},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-179516.pdf"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2017-16"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/102103"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039978"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0998"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2185"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2186"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2187"},{"type":"ADVISORY","url":"https://security.FreeBSD.org/advisories/FreeBSD-SA-17:12.openssl.asc"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201712-03"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20171208-0001/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180117-0002/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180419-0002/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2017/dsa-4065"},{"type":"ADVISORY","url":"https://www.digitalmunition.me/2017/12/cve-2017-3737-openssl-security-bypass-vulnerability/"},{"type":"ADVISORY","url":"https://www.openssl.org/news/secadv/20171207.txt"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/898fb884b706aaeb283de4812340bb0bde8476dc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"0"},{"last_affected":"e818b74be2170fbe957a07b0da4401c2b694b3b8"}],"database_specific":{"source":"CPE_FIELD","cpe":["cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2g:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2h:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2i:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2j:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2k:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2l:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl:1.0.2m:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.2b"},{"last_affected":"1.0.2c"},{"last_affected":"1.0.2d"},{"last_affected":"1.0.2e"},{"last_affected":"1.0.2f"},{"last_affected":"1.0.2g"},{"last_affected":"1.0.2h"},{"last_affected":"1.0.2i"},{"last_affected":"1.0.2j"},{"last_affected":"1.0.2k"},{"last_affected":"1.0.2l"},{"last_affected":"1.0.2m"}]}}],"versions":["OpenSSL_1_0_2u","OpenSSL_1_0_2t","OpenSSL_1_0_2s","OpenSSL_1_0_2r","OpenSSL_1_0_2q","OpenSSL_1_0_2p","OpenSSL_1_0_2o","OpenSSL_1_0_2n","OpenSSL_1_0_2m","OpenSSL_1_0_2l","OpenSSL_1_0_2k","OpenSSL_1_0_2j","OpenSSL_1_0_2i","OpenSSL_1_0_2h","OpenSSL_1_0_2g","OpenSSL_1_0_2f","OpenSSL_1_0_2e","OpenSSL_1_0_2d","OpenSSL_1_0_2c","OpenSSL_1_0_2b","OpenSSL_1_0_2a","OpenSSL_1_0_2","OpenSSL_1_0_2-post-reformat","OpenSSL_1_0_2-post-auto-reformat","OpenSSL_1_0_2-pre-auto-reformat","OpenSSL_1_0_2-pre-reformat","OpenSSL_1_0_2-beta3","OpenSSL_1_0_2-beta2","OpenSSL_1_0_2-beta1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-3737.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}