CVE-2004-0112
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD
Description
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Affected (233)
Products: Cisco: Firewall Services Module, Ciscoworks Common Management Foundation, Ciscoworks Common Services, Ios, Access Registrar, Application And Content Networking Software, Call Manager, Content Services Switch 11500, Css11000 Content Services Switch, Css Secure Content Accelerator, Gss 4480 Global Site Selector, Gss 4490 Global Site Selector, Mds 9000, Okena Stormwatch, Pix Firewall, Pix Firewall Software, Secure Content Accelerator, Threat Response, Webns · Hp: Aaa Server, Apache Based Web Server, Hp Ux, Wbem · Symantec: Clientless Vpn Gateway 4400 · +21 more
Show all products
Cisco: Firewall Services Module, Ciscoworks Common Management Foundation, Ciscoworks Common Services, Ios, Access Registrar, Application And Content Networking Software, Call Manager, Content Services Switch 11500, Css11000 Content Services Switch, Css Secure Content Accelerator, Gss 4480 Global Site Selector, Gss 4490 Global Site Selector, Mds 9000, Okena Stormwatch, Pix Firewall, Pix Firewall Software, Secure Content Accelerator, Threat Response, Webns · Hp: Aaa Server, Apache Based Web Server, Hp Ux, Wbem · Symantec: Clientless Vpn Gateway 4400 · Apple: Mac Os X, Mac Os X Server · Avaya: Converged Communications Server, Sg200, Sg203, Sg208, Sg5, Intuity Audix, S8300, S8500, S8700, Vsu · Freebsd: Freebsd · Openbsd: Openbsd · Redhat: Enterprise Linux, Enterprise Linux Desktop, Linux, Openssl · Sco: Openserver · 4d: Webstar · Bluecoat: Cacheos Ca Sa, Proxysg · Checkpoint: Firewall 1, Provider 1, Vpn 1 · Dell: Bsafe Ssl J · Forcepoint: Stonegate · Litespeedtech: Litespeed Web Server · Neoteris: Instant Virtual Extranet · Novell: Edirectory, Imanager · Openssl: Openssl · Securecomputing: Sidewinder · Sgi: Propack · Stonesoft: Servercluster, Stonebeat Fullcluster, Stonebeat Securitycluster, Stonebeat Webcluster · Sun: Crypto Accelerator 4000 · Tarantella: Tarantella Enterprise · Vmware: Gsx Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| Version 2.0.43.00 | |
| Version 5.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.3.3 | |
| Version 10.3.3 | |
| Version 2.0 | |
| Version 4.31.29 | |
| Version 4.31.29 | |
| All versions | |
| Version 4.2 | |
| Version 2.1 | |
| Version 2.2 | |
| Version 4.8 | |
| Version 11.00 | |
| Version 3.3 | |
| Version 3.0 | |
| Version 3.0 | |
| Version 7.2 | |
| Version 5.0.6 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.1(11)e | |
| Version 4.0 | |
| All versions | |
| Version r2.0.0 | |
| Version r2.0.0 | |
| Version r2.0.0 | |
| Version 10000_r2.0.1 | |
| Version 4.1.10 | |
| All versions | |
| All versions | |
| Version 4.1 | |
| Version next_generation_fp0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Version 1.0 | |
| All versions | |
| All versions | |
| All versions | |
| Version 3.2 | |
| Version 6.2.2_.111 | |
| Version 6.0 | |
| Version 10000 | |
| All versions | |
| Version 6.10 | |
| Version 3.0.1 | |
| Version 1.5.17 | |
| Version a.01.05.08 | |
| Version 1.0.1 | |
| Version 3.0 | |
| Version 8.0 | |
| Version 1.5 | |
| Version 0.9.6c | |
| Version 0.9.6-15 | |
| Version 5.2.0.01 | |
| Version 2.3 | |
| Version 2.5.2 | |
| Version 1_2.0 | |
| Version 2.0 | |
| Version 2.0 | |
| Version 1.0 | |
| Version 3.20 | |
| Version 2.0.1_build_2129 |
| Running on/with | Platform Versions |
|---|---|
Litespeedtech Litespeed Web Server | Version 1.0.2 |
References (58)
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc (unsafe URL)
Source: cve@mitre.org
Broken Link
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt (unsafe URL)
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken LinkThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Timeline
No history available yet.