The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
4d |
|
Apple |
|
Avaya |
|
Bluecoat |
|
Checkpoint |
|
Cisco |
|
Dell |
|
Forcepoint |
|
Freebsd |
|
Hp |
|
Litespeedtech |
|
Neoteris |
|
Novell |
|
Openbsd |
|
Openssl |
|
Redhat |
|
Sco |
|
Securecomputing |
|
Sgi |
|
Stonesoft |
|
Sun |
|
Symantec |
|
Tarantella |
|
Vmware |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
AND |
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Red Hat Enterprise Linux 3 | |||
openssl-0:0.9.7a-33.4 | cpe:/o:redhat:enterprise_linux:3 | RHSA-2004:120 | 2004-03-17T00:00:00Z |
openssl096b-0:0.9.6b-16 | cpe:/o:redhat:enterprise_linux:3 | RHSA-2004:120 | 2004-03-17T00:00:00Z |
Red Hat Linux 9 | |||
cpe:/o:redhat:linux:9 | RHSA-2004:121 | 2004-03-17T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2004-03-18T05:00:00
Updated: 2024-08-08T00:10:03.359Z
Reserved: 2004-02-02T00:00:00
Link: CVE-2004-0112
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2004-11-23T05:00:00.000
Modified: 2024-02-15T20:54:12.877
Link: CVE-2004-0112
Redhat