CVE-2003-0851
published 2003-12-01CVE-2003-0851: OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.41%
91.8th percentile
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | pix_firewall | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| cisco | pix_firewall_software | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m2h2-rm4v-5p5x: OpenSSL 0
ghsa_unreviewed·2022-05-03
CVE-2003-0851 [MEDIUM] GHSA-m2h2-rm4v-5p5x: OpenSSL 0
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
Red Hat
security flaw
vendor_redhat·2003-11-04·CVSS 5.0
CVE-2003-0851 [MEDIUM] security flaw
security flaw
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
Cisco
SSL Implementation Vulnerabilities
vendor_cisco·2003-09-30·CVSS 5.0
CVE-2003-0543 [MEDIUM] CWE-399 SSL Implementation Vulnerabilities
SSL Implementation Vulnerabilities
On September 30, 2003, new vulnerabilities in the
OpenSSL
implementation
for SSL were announced. This is referred to as the "first" vulnerability in
this document.
On November 4, 2003, another vulnerability in the
OpenSSL
implementation
for SSL, version 0.9.6, was announced. This is referred to as the "second"
vulnerability in this document.
An affected network device running an SSL server based on an affected
OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack
when presented with a malformed certificate by a client. The network device may
be vulnerable to this vulnerability even if it is configured to not
authenticate certificates from the client. There are workarounds available to
mitigate the effects of these vulnerabilities
Cisco
SSL Implementation Vulnerabilities
vendor_cisco
CVE-2003-0851 SSL Implementation Vulnerabilities
CVE-2003-0851: SSL Implementation Vulnerabilities
On September 30, 2003, new vulnerabilities in the OpenSSL implementation for SSL were announced. This is referred to as the "first" vulnerability in this document. On November 4, 2003, another vulnerability in the OpenSSL implementation for SSL, version 0.9.6, was announced. This is referred to as the "second" vulnerability in this document. An affected network device running an SSL server based on an affected OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack when presented with a malformed certificate by a client. The network device may be vulnerable to this vulnerability even if it is configured to not authenticate certificates from the client. There are
CWE: CWE-399, CWE-399
Bug IDs: CSCec46274, CSCec31274, CSC
No detection rules found.
No public exploits indexed.
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-003.txt.ascftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.aschttp://marc.info/?l=bugtraq&m=106796246511667&w=2http://marc.info/?l=bugtraq&m=108403850228012&w=2http://rhn.redhat.com/errata/RHSA-2004-119.htmlhttp://secunia.com/advisories/17381http://www.cisco.com/warp/public/707/cisco-sa-20030930-ssl.shtmlhttp://www.kb.cert.org/vuls/id/412478http://www.openssl.org/news/secadv_20031104.txthttp://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.htmlhttp://www.securityfocus.com/bid/8970https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5528ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-003.txt.ascftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.aschttp://marc.info/?l=bugtraq&m=106796246511667&w=2http://marc.info/?l=bugtraq&m=108403850228012&w=2http://rhn.redhat.com/errata/RHSA-2004-119.htmlhttp://secunia.com/advisories/17381http://www.cisco.com/warp/public/707/cisco-sa-20030930-ssl.shtmlhttp://www.kb.cert.org/vuls/id/412478http://www.openssl.org/news/secadv_20031104.txthttp://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.htmlhttp://www.securityfocus.com/bid/8970https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5528
2003-12-01
Published