CVE-2008-0891
published 2008-05-29CVE-2008-0891: Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.56%
90.5th percentile
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8g-10.1 (bookworm) | openssl 0.9.8g-10.1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2008-06-26·CVSS 4.3
CVE-2008-0891 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL vulnerabilities
It was discovered that OpenSSL was vulnerable to a double-free
when using TLS server extensions. A remote attacker could send a
crafted packet and cause a denial of service via application crash
in applications linked against OpenSSL. Ubuntu 8.04 LTS does not
compile TLS server extensions by default. (CVE-2008-0891)
It was discovered that OpenSSL could dereference a NULL pointer.
If a user or automated system were tricked into connecting to a
malicious server with particular cipher suites, a remote attacker
could cause a denial of service via application crash.
(CVE-2008-1672)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
openssl: Server Name extension crash
vendor_redhat·2008-05-28·CVSS 4.3
CVE-2008-0891 [MEDIUM] openssl: Server Name extension crash
openssl: Server Name extension crash
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
Statement: Not vulnerable. This issue did not affect the versions of OpenSSL as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2008-0891: openssl - Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name...
vendor_debian·2008·CVSS 4.3
CVE-2008-0891 [MEDIUM] CVE-2008-0891: openssl - Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name...
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.9.8g-10.1)
bullseye: resolved (fixed in 0.9.8g-10.1)
forky: resolved (fixed in 0.9.8g-10.1)
sid: resolved (fixed in 0.9.8g-10.1)
trixie: resolved (fixed in 0.9.8g-10.1)
GHSA
GHSA-8v7x-8cw9-9c5c: Double free vulnerability in OpenSSL 0
ghsa_unreviewed·2022-05-01
CVE-2008-0891 [MEDIUM] GHSA-8v7x-8cw9-9c5c: Double free vulnerability in OpenSSL 0
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
OSV
CVE-2008-0891: Double free vulnerability in OpenSSL 0
osv·2008-05-29·CVSS 4.3
CVE-2008-0891 [MEDIUM] CVE-2008-0891: Double free vulnerability in OpenSSL 0
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
http://cert.fi/haavoittuvuudet/2008/advisory-openssl.htmlhttp://secunia.com/advisories/30405http://secunia.com/advisories/30460http://secunia.com/advisories/30825http://secunia.com/advisories/30852http://secunia.com/advisories/30868http://secunia.com/advisories/31228http://secunia.com/advisories/31288http://security.gentoo.org/glsa/glsa-200806-08.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.562004http://sourceforge.net/project/shownotes.php?release_id=615606http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=738400http://www.kb.cert.org/vuls/id/661475http://www.mandriva.com/security/advisories?name=MDVSA-2008:107http://www.openssl.org/news/secadv_20080528.txthttp://www.securityfocus.com/bid/29405http://www.securitytracker.com/id?1020121http://www.ubuntu.com/usn/usn-620-1http://www.vupen.com/english/advisories/2008/1680http://www.vupen.com/english/advisories/2008/1937/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42666https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01029.htmlhttp://cert.fi/haavoittuvuudet/2008/advisory-openssl.htmlhttp://secunia.com/advisories/30405http://secunia.com/advisories/30460http://secunia.com/advisories/30825http://secunia.com/advisories/30852http://secunia.com/advisories/30868http://secunia.com/advisories/31228http://secunia.com/advisories/31288http://security.gentoo.org/glsa/glsa-200806-08.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.562004http://sourceforge.net/project/shownotes.php?release_id=615606http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=738400http://www.kb.cert.org/vuls/id/661475http://www.mandriva.com/security/advisories?name=MDVSA-2008:107http://www.openssl.org/news/secadv_20080528.txthttp://www.securityfocus.com/bid/29405http://www.securitytracker.com/id?1020121http://www.ubuntu.com/usn/usn-620-1http://www.vupen.com/english/advisories/2008/1680http://www.vupen.com/english/advisories/2008/1937/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42666https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01029.html
2008-05-29
Published