OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.02393.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
4d
Subscribe
|
Webstar
Subscribe
|
|
Apple
Subscribe
|
|
|
Avaya
Subscribe
|
|
|
Bluecoat
Subscribe
|
|
|
Checkpoint
Subscribe
|
|
|
Cisco
Subscribe
|
Access Registrar
Subscribe
Application And Content Networking Software
Subscribe
Call Manager
Subscribe
Ciscoworks Common Management Foundation
Subscribe
Ciscoworks Common Services
Subscribe
Content Services Switch 11500
Subscribe
Css11000 Content Services Switch
Subscribe
Css Secure Content Accelerator
Subscribe
Firewall Services Module
Subscribe
Gss 4480 Global Site Selector
Subscribe
Gss 4490 Global Site Selector
Subscribe
Ios
Subscribe
Mds 9000
Subscribe
Okena Stormwatch
Subscribe
Pix Firewall
Subscribe
Pix Firewall Software
Subscribe
Secure Content Accelerator
Subscribe
Threat Response
Subscribe
Webns
Subscribe
|
|
Dell
Subscribe
|
Bsafe Ssl-j
Subscribe
|
|
Freebsd
Subscribe
|
Freebsd
Subscribe
|
|
Hp
Subscribe
|
|
|
Lite
Subscribe
|
Speed Technologies Litespeed Web Server
Subscribe
|
|
Neoteris
Subscribe
|
Instant Virtual Extranet
Subscribe
|
|
Novell
Subscribe
|
|
|
Openbsd
Subscribe
|
Openbsd
Subscribe
|
|
Openssl
Subscribe
|
Openssl
Subscribe
|
|
Redhat
Subscribe
|
|
|
Sco
Subscribe
|
Openserver
Subscribe
|
|
Securecomputing
Subscribe
|
Sidewinder
Subscribe
|
|
Sgi
Subscribe
|
Propack
Subscribe
|
|
Stonesoft
Subscribe
|
|
|
Sun
Subscribe
|
Crypto Accelerator 4000
Subscribe
|
|
Symantec
Subscribe
|
Clientless Vpn Gateway 4400
Subscribe
|
|
Tarantella
Subscribe
|
Tarantella Enterprise
Subscribe
|
|
Vmware
Subscribe
|
Gsx Server
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
| AND |
|
| Package | CPE | Advisory | Released Date |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | |||
| openssl-0:0.9.7a-33.4 | cpe:/o:redhat:enterprise_linux:3 | RHSA-2004:120 | 2004-03-17T00:00:00Z |
| openssl096b-0:0.9.6b-16 | cpe:/o:redhat:enterprise_linux:3 | RHSA-2004:120 | 2004-03-17T00:00:00Z |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | |||
| cpe:/o:redhat:enterprise_linux:2.1 | RHSA-2004:119 | 2004-03-17T00:00:00Z | |
| Red Hat Enterprise Linux ES version 2.1 | |||
| cpe:/o:redhat:enterprise_linux:2.1 | RHSA-2004:119 | 2004-03-17T00:00:00Z | |
| Red Hat Enterprise Linux WS version 2.1 | |||
| cpe:/o:redhat:enterprise_linux:2.1 | RHSA-2004:119 | 2004-03-17T00:00:00Z | |
| Red Hat Linux 9 | |||
| cpe:/o:redhat:linux:9 | RHSA-2004:121 | 2004-03-17T00:00:00Z | |
| Red Hat Linux Advanced Workstation 2.1 | |||
| cpe:/o:redhat:enterprise_linux:2.1 | RHSA-2004:119 | 2004-03-17T00:00:00Z | |
| Red Hat Stronghold 4 | |||
| cpe:/a:redhat:stronghold:4 | RHSA-2004:139 | 2004-03-17T00:00:00Z | |
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2004-0081 | OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:01:23.650Z
Reserved: 2004-01-19T00:00:00
Link: CVE-2004-0081
No data.
Status : Deferred
Published: 2004-11-23T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2004-0081
OpenCVE Enrichment
No data.
Weaknesses
EUVD