CVE-2004-0112
published 2004-11-23CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
10.42%
95.2th percentile
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Affected
210 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| 4d | webstar | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| avaya | converged_communications_server | — | — |
| avaya | intuity_audix | — | — |
| avaya | intuity_audix | — | — |
| avaya | intuity_audix | — | — |
| avaya | s8300 | — | — |
| avaya | s8300 | — | — |
| avaya | s8500 | — | — |
| avaya | s8500 | — | — |
| avaya | s8700 | — | — |
| avaya | s8700 | — | — |
| avaya | sg200 | — | — |
| avaya | sg200 | — | — |
| avaya | sg203 | — | — |
| avaya | sg203 | — | — |
| avaya | sg208 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ph6p-3j2f-xq2g: The SSL/TLS handshaking code in OpenSSL 0
ghsa_unreviewed·2022-05-03
CVE-2004-0112 [MEDIUM] GHSA-ph6p-3j2f-xq2g: The SSL/TLS handshaking code in OpenSSL 0
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
GHSA
GHSA-3hr7-2v28-gj4j: Multiple vulnerabilities in the OpenSSL ASN
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2005-1730 [HIGH] GHSA-3hr7-2v28-gj4j: Multiple vulnerabilities in the OpenSSL ASN
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.
OSV
CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0
osv·2004-11-23·CVSS 5.0
CVE-2004-0112 [MEDIUM] CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Red Hat
security flaw
vendor_redhat·2004-03-17·CVSS 5.0
CVE-2004-0112 [MEDIUM] security flaw
security flaw
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Cisco
Cisco OpenSSL Implementation Vulnerability
vendor_cisco·2004-03-17
CVE-2004-0079 CWE-399 Cisco OpenSSL Implementation Vulnerability
Cisco OpenSSL Implementation Vulnerability
A new vulnerability in the
OpenSSL
implementation for
SSL has been announced on March 17, 2004.
An affected network device running an SSL server based on an affected
OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack.
There are workarounds available to mitigate the effects of this vulnerability
on Cisco products in the workaround section of this advisory. Cisco is
providing fixed software, and recommends that customers upgrade to it when it
is available.
This advisory will be posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040317-openssl.
Debian
CVE-2004-0112: openssl - The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using K...
vendor_debian·2004·CVSS 5.0
CVE-2004-0112 [MEDIUM] CVE-2004-0112: openssl - The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using K...
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 0.9.7d-1)
bullseye: resolved (fixed in 0.9.7d-1)
forky: resolved (fixed in 0.9.7d-1)
sid: resolved (fixed in 0.9.7d-1)
trixie: resolved (fixed in 0.9.7d-1)
Red Hat
CVE-2005-1730: Multiple vulnerabilities in the OpenSSL ASN
vendor_redhat·CVSS 5.0
CVE-2005-1730 [MEDIUM] CVE-2005-1730: Multiple vulnerabilities in the OpenSSL ASN
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.
Statement: Based on our research we believe that the "OpenSSL ASN.1 brute forcer." is actually exploiting flaws CVE-2003-0543, CVE-2003-0544, CVE-2003-0545. Those issues are all addressed in Red Hat Enterprise Linux and therefore CVE-2005-1730 is a duplicate assignment.
Cisco
Cisco OpenSSL Implementation Vulnerability
vendor_cisco
CVE-2004-0112 Cisco OpenSSL Implementation Vulnerability
CVE-2004-0112: Cisco OpenSSL Implementation Vulnerability
A new vulnerability in the OpenSSL implementation for SSL has been announced on March 17, 2004. An affected network device running an SSL server based on an affected OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack. There are
CWE: CWE-399, CWE-399
Bug IDs: CSCee00041, CSCed90672, CSCee02055, CSCed96246, CSCee01234
No detection rules found.
No public exploits indexed.
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.ascftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834http://docs.info.apple.com/article.html?artnum=61798http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlhttp://lists.apple.com/mhonarc/security-announce/msg00045.htmlhttp://marc.info/?l=bugtraq&m=107953412903636&w=2http://marc.info/?l=bugtraq&m=108403806509920&w=2http://secunia.com/advisories/11139http://security.gentoo.org/glsa/glsa-200403-03.xmlhttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524http://www.ciac.org/ciac/bulletins/o-101.shtmlhttp://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtmlhttp://www.kb.cert.org/vuls/id/484726http://www.mandriva.com/security/advisories?name=MDKSA-2004:023http://www.novell.com/linux/security/advisories/2004_07_openssl.htmlhttp://www.openssl.org/news/secadv_20040317.txthttp://www.redhat.com/support/errata/RHSA-2004-120.htmlhttp://www.redhat.com/support/errata/RHSA-2004-121.htmlhttp://www.securityfocus.com/bid/9899http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961http://www.trustix.org/errata/2004/0012http://www.uniras.gov.uk/vuls/2004/224012/index.htmhttp://www.us-cert.gov/cas/techalerts/TA04-078A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/15508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1049https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A928https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9580ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.ascftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txthttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834http://docs.info.apple.com/article.html?artnum=61798http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlhttp://lists.apple.com/mhonarc/security-announce/msg00045.htmlhttp://marc.info/?l=bugtraq&m=107953412903636&w=2http://marc.info/?l=bugtraq&m=108403806509920&w=2http://secunia.com/advisories/11139http://security.gentoo.org/glsa/glsa-200403-03.xmlhttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524http://www.ciac.org/ciac/bulletins/o-101.shtmlhttp://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtmlhttp://www.kb.cert.org/vuls/id/484726http://www.mandriva.com/security/advisories?name=MDKSA-2004:023http://www.novell.com/linux/security/advisories/2004_07_openssl.htmlhttp://www.openssl.org/news/secadv_20040317.txthttp://www.redhat.com/support/errata/RHSA-2004-120.htmlhttp://www.redhat.com/support/errata/RHSA-2004-121.htmlhttp://www.securityfocus.com/bid/9899http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961http://www.trustix.org/errata/2004/0012http://www.uniras.gov.uk/vuls/2004/224012/index.htmhttp://www.us-cert.gov/cas/techalerts/TA04-078A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/15508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1049https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A928https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9580
2004-11-23
Published