CVE-2007-5135Off-by-one Error in Openssl

CWE-193Off-by-one Error8 documents8 sources
Severity
6.8MEDIUMNVD
OSV10.0
EPSS
47.5%
top 2.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 27
Latest updateMay 3

Description

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

debiandebian/openssl< openssl 0.9.8e-9 (bookworm)
Debianopenssl/openssl< 0.9.8e-9+3
NVDopenssl/openssl20 versions+19

🔴Vulnerability Details

2
GHSA
GHSA-jvv3-c5fw-96v6: Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 02022-05-03
OSV
CVE-2007-5135: Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 02007-09-27

📋Vendor Advisories

5
VMware
Updated service console patches.2008-01-07
BSD
FreeBSD-SA-07:08.openssl: Buffer overflow in OpenSSL SSL_get_shared_ciphers()2007-10-03
Ubuntu
openssl vulnerabilities2007-09-28
Red Hat
openssl: SSL_get_shared_ciphers() off-by-one2007-09-27
Debian
CVE-2007-5135: openssl - Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0...2007