CVE-2004-0081
published 2004-11-23CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.23%
93.7th percentile
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
Affected
229 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| avaya | converged_communications_server | — | — |
| avaya | intuity_audix | — | — |
| avaya | intuity_audix | — | — |
| avaya | intuity_audix | — | — |
| avaya | s8300 | — | — |
| avaya | s8300 | — | — |
| avaya | s8500 | — | — |
| avaya | s8500 | — | — |
| avaya | s8700 | — | — |
| avaya | s8700 | — | — |
| avaya | sg200 | — | — |
| avaya | sg200 | — | — |
| avaya | sg203 | — | — |
| avaya | sg203 | — | — |
| avaya | sg208 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2004-03-17·CVSS 5.0
CVE-2004-0081 [MEDIUM] security flaw
security flaw
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
Cisco
Cisco OpenSSL Implementation Vulnerability
vendor_cisco·2004-03-17
CVE-2004-0079 CWE-399 Cisco OpenSSL Implementation Vulnerability
Cisco OpenSSL Implementation Vulnerability
A new vulnerability in the
OpenSSL
implementation for
SSL has been announced on March 17, 2004.
An affected network device running an SSL server based on an affected
OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack.
There are workarounds available to mitigate the effects of this vulnerability
on Cisco products in the workaround section of this advisory. Cisco is
providing fixed software, and recommends that customers upgrade to it when it
is available.
This advisory will be posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040317-openssl.
Debian
CVE-2004-0081: openssl - OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, whic...
vendor_debian·2004·CVSS 5.0
CVE-2004-0081 [MEDIUM] CVE-2004-0081: openssl - OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, whic...
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
Scope: local
bookworm: resolved (fixed in 0.9.6d-1)
bullseye: resolved (fixed in 0.9.6d-1)
forky: resolved (fixed in 0.9.6d-1)
sid: resolved (fixed in 0.9.6d-1)
trixie: resolved (fixed in 0.9.6d-1)
Red Hat
CVE-2005-1730: Multiple vulnerabilities in the OpenSSL ASN
vendor_redhat·CVSS 5.0
CVE-2005-1730 [MEDIUM] CVE-2005-1730: Multiple vulnerabilities in the OpenSSL ASN
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.
Statement: Based on our research we believe that the "OpenSSL ASN.1 brute forcer." is actually exploiting flaws CVE-2003-0543, CVE-2003-0544, CVE-2003-0545. Those issues are all addressed in Red Hat Enterprise Linux and therefore CVE-2005-1730 is a duplicate assignment.
Cisco
Cisco OpenSSL Implementation Vulnerability
vendor_cisco
CVE-2004-0081 Cisco OpenSSL Implementation Vulnerability
CVE-2004-0081: Cisco OpenSSL Implementation Vulnerability
A new vulnerability in the OpenSSL implementation for SSL has been announced on March 17, 2004. An affected network device running an SSL server based on an affected OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack. There are
CWE: CWE-399, CWE-399
Bug IDs: CSCee00041, CSCed90672, CSCee02055, CSCed96246, CSCee01234
GHSA
GHSA-pcwf-qwvv-qjg3: OpenSSL 0
ghsa_unreviewed·2022-05-03
CVE-2004-0081 [MEDIUM] GHSA-pcwf-qwvv-qjg3: OpenSSL 0
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
GHSA
GHSA-3hr7-2v28-gj4j: Multiple vulnerabilities in the OpenSSL ASN
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2005-1730 [HIGH] GHSA-3hr7-2v28-gj4j: Multiple vulnerabilities in the OpenSSL ASN
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.
OSV
CVE-2004-0081: OpenSSL 0
osv·2004-11-23·CVSS 5.0
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-0081 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2004-0081 [MEDIUM] CVE-2004-0081 security flaw
CVE-2004-0081 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
Bugzilla
CAN-2003-0977 fix pushed for RH9, but not FC1
bugzilla·2004-03-20
[MEDIUM] CAN-2003-0977 fix pushed for RH9, but not FC1
CAN-2003-0977 fix pushed for RH9, but not FC1
Description of problem:
CAN-2003-0977 fix pushed for RH9, but not FC1
Version-Release number of selected component (if applicable):
cvs-1.11.5-3
Additional info:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=111221#c5
https://rhn.redhat.com/errata/RHSA-2004-003.html
http://ccvs.cvshome.org/servlets/NewsItemView?newsID=84
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0081.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0977
Discussion:
A rebuild from cvs-1.11.11-1 (or higher) from Fedora Development
at Fedora Core 1 solves the problem, so maybe one of the Red Hat
maintainers could do that? Would be very nice :)
BTW: Maybe the kerberos 4 support has to be disabled.
---
Maybe that issue is fixed soon by one of
Bugzilla
CAN-2004-0081 OpenSSL flaw
bugzilla·2004-03-08
[MEDIUM] CAN-2004-0081 OpenSSL flaw
CAN-2004-0081 OpenSSL flaw
Testing performed by the OpenSSL group using the Codenomicon
TLS Test Tool uncovered a bug in older versions of OpenSSL
0.9.6 prior to 0.9.6d that can lead to a Denial of Service
attack (infinite loop). The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0081 to this issue.
CAN-2004-0081 Affects: 2.1AS 2.1AW 2.1ES 2.1WS (+095a)
Notified by NISCC
Embargoed until March 17th 2004, 1400UTC
Discussion:
An errata has been issued which should help the problem described in this bug report.
This report is therefore being closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, please follow the link below. You may reopen
this bug report if the solution does not work fo
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txtftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834http://fedoranews.org/updates/FEDORA-2004-095.shtmlhttp://marc.info/?l=bugtraq&m=107955049331965&w=2http://marc.info/?l=bugtraq&m=108403850228012&w=2http://rhn.redhat.com/errata/RHSA-2004-119.htmlhttp://secunia.com/advisories/11139http://security.gentoo.org/glsa/glsa-200403-03.xmlhttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtmlhttp://www.debian.org/security/2004/dsa-465http://www.kb.cert.org/vuls/id/465542http://www.linuxsecurity.com/advisories/engarde_advisory-4135.htmlhttp://www.redhat.com/support/errata/RHSA-2004-120.htmlhttp://www.redhat.com/support/errata/RHSA-2004-121.htmlhttp://www.redhat.com/support/errata/RHSA-2004-139.htmlhttp://www.securityfocus.com/bid/9899http://www.trustix.org/errata/2004/0012http://www.uniras.gov.uk/vuls/2004/224012/index.htmhttp://www.us-cert.gov/cas/techalerts/TA04-078A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/15509https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11755https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A871https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A902ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txtftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834http://fedoranews.org/updates/FEDORA-2004-095.shtmlhttp://marc.info/?l=bugtraq&m=107955049331965&w=2http://marc.info/?l=bugtraq&m=108403850228012&w=2http://rhn.redhat.com/errata/RHSA-2004-119.htmlhttp://secunia.com/advisories/11139http://security.gentoo.org/glsa/glsa-200403-03.xmlhttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtmlhttp://www.debian.org/security/2004/dsa-465http://www.kb.cert.org/vuls/id/465542http://www.linuxsecurity.com/advisories/engarde_advisory-4135.htmlhttp://www.redhat.com/support/errata/RHSA-2004-120.htmlhttp://www.redhat.com/support/errata/RHSA-2004-121.htmlhttp://www.redhat.com/support/errata/RHSA-2004-139.htmlhttp://www.securityfocus.com/bid/9899http://www.trustix.org/errata/2004/0012http://www.uniras.gov.uk/vuls/2004/224012/index.htmhttp://www.us-cert.gov/cas/techalerts/TA04-078A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/15509https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11755https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A871https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A902
2004-11-23
Published