← Back

CVE-2004-0112

nvd nist
Published: Nov 23, 2004Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

Affected (233)

Show all products
19 products
Firewall Services Module
Ciscoworks Common Services
Ios
Access Registrar
Call Manager
Content Services Switch 11500
Css11000 Content Services Switch
Css Secure Content Accelerator
Gss 4480 Global Site Selector
Gss 4490 Global Site Selector
Mds 9000
Okena Stormwatch
Pix Firewall
Pix Firewall Software
Secure Content Accelerator
Threat Response
Webns
4 products
Aaa Server
Apache Based Web Server
Hp Ux
Wbem
1 product
Clientless Vpn Gateway 4400
2 products
Mac Os X
Mac Os X Server
10 products
Converged Communications Server
Sg200
Sg203
Sg208
Sg5
Intuity Audix
S8300
S8500
S8700
Vsu
1 product
Freebsd
1 product
Openbsd
4 products
Enterprise Linux
Enterprise Linux Desktop
Linux
Openssl
1 product
Openserver
1 product
Webstar
2 products
Cacheos Ca Sa
Proxysg
3 products
Firewall 1
Provider 1
Vpn 1
1 product
Bsafe Ssl J
1 product
Stonegate
1 product
Litespeed Web Server
1 product
Instant Virtual Extranet
2 products
Edirectory
Imanager
1 product
Openssl
Sidewinder
1 product
Propack
4 products
Servercluster
Stonebeat Fullcluster
Stonebeat Securitycluster
Stonebeat Webcluster
1 product
Crypto Accelerator 4000
1 product
Tarantella Enterprise
1 product
Gsx Server
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
All versions
Version 1.1.2
Version 1.1.3
Version 1.1_(3.005)
Version 2.1_(0.208)
All versions
Hp
Version 2.0.43.00
Version 2.0.43.04
Version 5.0
Configuration B
37 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.3.3
Version 10.3.3
Version 2.0
Avaya
Version 4.31.29
Version 4.4
Avaya
Version 4.31.29
Version 4.4
Avaya
All versions
Version 4.4
Avaya
Version 4.2
Version 4.3
Version 4.4
Version 2.1
Version 2.2
Freebsd
Version 4.8
Version 4.8 releng
Version 4.9
Version 5.1
Version 5.1 release
Version 5.1 releng
Version 5.2.1 release
Version 5.2
Hp
Version 11.00
Version 11.11
Version 11.23
Version 8.05
Openbsd
Version 3.3
Version 3.4
Redhat
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Redhat
Version 7.2
Version 7.3
Version 8.0
Sco
Version 5.0.6
Version 5.0.7
Configuration C
187 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 12.1(11)e
Version 12.1(11b)e12
Version 12.1(11b)e14
Version 12.1(11b)e
Version 12.1(13)e9
Version 12.1(19)e1
Version 12.2(14)sy1
Version 12.2(14)sy
Version 12.2sy
Version 12.2za
4d
Version 4.0
Version 5.2.1
Version 5.2.2
Version 5.2.3
Version 5.2.4
Version 5.2
Version 5.3.1
Version 5.3
Avaya
All versions
Version 5.1.46
Version s3210
Version s3400
Avaya
Version r2.0.0
Version r2.0.1
Avaya
Version r2.0.0
Version r2.0.1
Avaya
Version r2.0.0
Version r2.0.1
Avaya
Version 10000_r2.0.1
Version 100_r2.0.1
Version 2000_r2.0.1
Version 5000_r2.0.1
Version 500
Version 5
Version 5x
Version 7500_r2.0.1
Bluecoat
Version 4.1.10
Version 4.1.12
All versions
Checkpoint
All versions
Version 2.0
Version next_generation_fp0
Version next_generation_fp1
Version next_generation_fp2
Checkpoint
Version 4.1
Version 4.1 sp1
Version 4.1 sp2
Version 4.1 sp3
Version 4.1 sp4
Checkpoint
Version next_generation_fp0
Version next_generation_fp1
Version next_generation_fp2
Version vsx_ng_with_application_intelligence
All versions
All versions
All versions
All versions
All versions
Cisco
Version 1.0
Version 2.0
All versions
All versions
All versions
Version 3.2
Version 6.2.2_.111
Cisco
Version 6.0
Version 6.0(1)
Version 6.0(2)
Version 6.0(3)
Version 6.0(4.101)
Version 6.0(4)
Version 6.1
Version 6.1(1)
Version 6.1(2)
Version 6.1(3)
Version 6.1(4)
Version 6.1(5)
Version 6.2
Version 6.2(1)
Version 6.2(2)
Version 6.2(3.100)
Version 6.2(3)
Version 6.3
Version 6.3(1)
Version 6.3(2)
Version 6.3(3.102)
Version 6.3(3.109)
Version 10000
All versions
Cisco
Version 6.10
Version 6.10_b4
Version 7.10
Version 7.10_.0.06s
Version 7.1_0.1.02
Version 7.1_0.2.06
Version 7.2_0.0.03
Dell
Version 3.0.1
Version 3.0
Version 3.1
Forcepoint
Version 1.5.17
Version 1.5.18
Version 1.6.2
Version 1.6.3
Version 1.7.1
Version 1.7.2
Version 1.7
Version 2.0.1
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Version 2.1
Version 2.2.1
Version 2.2.4
Version 2.2
Hp
Version a.01.05.08
Version a.02.00.00
Version a.02.00.01
Version 1.0.1
Neoteris
Version 3.0
Version 3.1
Version 3.2
Version 3.3.1
Version 3.3
Novell
Version 8.0
Version 8.5.12a
Version 8.5.27
Version 8.5
Version 8.6.2
Version 8.7.1
Version 8.7.1 sp1
Version 8.7
Novell
Version 1.5
Version 2.0
Openssl
Version 0.9.6c
Version 0.9.6d
Version 0.9.6e
Version 0.9.6f
Version 0.9.6g
Version 0.9.6h
Version 0.9.6i
Version 0.9.6j
Version 0.9.6k
Version 0.9.7
Version 0.9.7 beta1
Version 0.9.7 beta2
Version 0.9.7 beta3
Version 0.9.7a
Version 0.9.7b
Version 0.9.7c
Redhat
Version 0.9.6-15
Version 0.9.6b-3
Version 0.9.7a-2
Version 0.9.7a-2
Version 0.9.7a-2
Securecomputing
Version 5.2.0.01
Version 5.2.0.02
Version 5.2.0.03
Version 5.2.0.04
Version 5.2.1.02
Version 5.2.1
Version 5.2
Sgi
Version 2.3
Version 2.4
Version 3.0
Stonesoft
Version 2.5.2
Version 2.5
Stonesoft
Version 1_2.0
Version 1_3.0
Version 2.0
Version 2.5
Version 3.0
Stonesoft
Version 2.0
Version 2.5
Stonesoft
Version 2.0
Version 2.5
Version 1.0
Tarantella
Version 3.20
Version 3.30
Version 3.40
Vmware
Version 2.0.1_build_2129
Version 2.0
Version 2.5.1
Version 2.5.1_build_5336
Version 3.0_build_7592
Running on/withPlatform Versions
Litespeedtech
Litespeed Web Server
Version 1.0.2
Litespeedtech
Litespeed Web Server
Version 1.0.3
Litespeedtech
Litespeed Web Server
Version 1.1.1
Litespeedtech
Litespeed Web Server
Version 1.1
Litespeedtech
Litespeed Web Server
Version 1.2.1
Litespeedtech
Litespeed Web Server
Version 1.2.2
Litespeedtech
Litespeed Web Server
Version 1.2 rc1
Litespeedtech
Litespeed Web Server
Version 1.2 rc2
Litespeedtech
Litespeed Web Server
Version 1.3
Litespeedtech
Litespeed Web Server
Version 1.3 rc1
Litespeedtech
Litespeed Web Server
Version 1.3 rc2
Litespeedtech
Litespeed Web Server
Version 1.3 rc3

References (58)

ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc (unsafe URL)
Source: cve@mitre.org
Broken Link
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt (unsafe URL)
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken LinkThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.