CVE-2008-1672
published 2008-05-29CVE-2008-1672: OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
5.00%
91.3th percentile
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | openssl | < openssl 0.9.8g-10.1 (bookworm) | openssl 0.9.8g-10.1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
| openssl | openssl | >= 0 < 0.9.8g-10.1 | 0.9.8g-10.1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2008-06-26·CVSS 4.3
CVE-2008-0891 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL vulnerabilities
It was discovered that OpenSSL was vulnerable to a double-free
when using TLS server extensions. A remote attacker could send a
crafted packet and cause a denial of service via application crash
in applications linked against OpenSSL. Ubuntu 8.04 LTS does not
compile TLS server extensions by default. (CVE-2008-0891)
It was discovered that OpenSSL could dereference a NULL pointer.
If a user or automated system were tricked into connecting to a
malicious server with particular cipher suites, a remote attacker
could cause a denial of service via application crash.
(CVE-2008-1672)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
openssl: Omit Server Key Exchange message crash
vendor_redhat·2008-05-28·CVSS 4.3
CVE-2008-1672 [MEDIUM] openssl: Omit Server Key Exchange message crash
openssl: Omit Server Key Exchange message crash
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
Statement: Not vulnerable. This issue did not affect the versions of OpenSSL as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2008-1672: openssl - OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (...
vendor_debian·2008·CVSS 4.3
CVE-2008-1672 [MEDIUM] CVE-2008-1672: openssl - OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (...
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.9.8g-10.1)
bullseye: resolved (fixed in 0.9.8g-10.1)
forky: resolved (fixed in 0.9.8g-10.1)
sid: resolved (fixed in 0.9.8g-10.1)
trixie: resolved (fixed in 0.9.8g-10.1)
GHSA
GHSA-322g-pxmj-97cc: OpenSSL 0
ghsa_unreviewed·2022-05-01
CVE-2008-1672 [MEDIUM] CWE-476 GHSA-322g-pxmj-97cc: OpenSSL 0
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
OSV
CVE-2008-1672: OpenSSL 0
osv·2008-05-29·CVSS 4.3
CVE-2008-1672 [MEDIUM] CVE-2008-1672: OpenSSL 0
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-1672 openssl: Omit Server Key Exchange message crash
bugzilla·2008-05-27·CVSS 4.3
CVE-2008-1672 [MEDIUM] CVE-2008-1672 openssl: Omit Server Key Exchange message crash
CVE-2008-1672 openssl: Omit Server Key Exchange message crash
CERT/FI identified following issue affecting OpenSSL:
Testing using the Codenomicon TLS test suite discovered a flaw if the
'Server Key exchange message' is omitted from a TLS handshake in
OpenSSL 0.9.8f and OpenSSL 0.9.8g. If a client connects to a
malicious server with particular cipher suites, the server could cause
the client to crash. (CVE-2008-1672).
Please note this issue does not affect any other released versions of
OpenSSL.
Discussion:
Created attachment 306751
Upstream patch
---
This issue does not affect openssl packages as shipped in Red Hat Enterprise
Linux 2.1, 3, 4 and 5, and Fedora 7 and 8. Only upstream versions 0.9.8f and
0.9.8g were affected, currently only shipped in Fedora 9 and Rawhide.
---
Public
arXiv
CEBin: A Cost-Effective Framework for Large-Scale Binary Code Similarity Detection
arxiv_fulltext·2024-02-29
CEBin: A Cost-Effective Framework for Large-Scale Binary Code Similarity Detection
: A Cost-Effective Framework for Large-Scale Binary Code Similarity Detection
Hao Wang^1, Zeyu Gao^1, Chao Zhang^1, Mingyang Sun^2, Yuchen Zhou^3, Han Qiu^1, Xi Xiao^4
Hao Wang, Zeyu Gao, Chao Zhang, Mingyang Sun, Yuchen Zhou, Han Qiu, Xi Xiao
^1Tsinghua University, Beijing, China
^2University of Electronic Science and Technology of China, Chengdu, China
^3Beijing University of Technology, Beijing, China
^4Tsinghua University, Shenzhen, China
hao-wang20,[email protected],chaoz,[email protected]
[email protected],[email protected],[email protected]
Wang, et al.
## Abstract
Binary code similarity detection (BCSD) is a fundamental technique for various application.
Many BCSD solutions have been proposed recently, which mostly are embed
http://cert.fi/haavoittuvuudet/2008/advisory-openssl.htmlhttp://secunia.com/advisories/30405http://secunia.com/advisories/30460http://secunia.com/advisories/30825http://secunia.com/advisories/30852http://secunia.com/advisories/30868http://secunia.com/advisories/31228http://secunia.com/advisories/31288http://security.gentoo.org/glsa/glsa-200806-08.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.562004http://sourceforge.net/project/shownotes.php?release_id=615606http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=738400http://www.kb.cert.org/vuls/id/520586http://www.mandriva.com/security/advisories?name=MDVSA-2008:107http://www.openssl.org/news/secadv_20080528.txthttp://www.securityfocus.com/archive/1/492932/100/0/threadedhttp://www.securityfocus.com/bid/29405http://www.securitytracker.com/id?1020122http://www.ubuntu.com/usn/usn-620-1http://www.vupen.com/english/advisories/2008/1680http://www.vupen.com/english/advisories/2008/1937/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42667https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01029.htmlhttp://cert.fi/haavoittuvuudet/2008/advisory-openssl.htmlhttp://secunia.com/advisories/30405http://secunia.com/advisories/30460http://secunia.com/advisories/30825http://secunia.com/advisories/30852http://secunia.com/advisories/30868http://secunia.com/advisories/31228http://secunia.com/advisories/31288http://security.gentoo.org/glsa/glsa-200806-08.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.562004http://sourceforge.net/project/shownotes.php?release_id=615606http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=738400http://www.kb.cert.org/vuls/id/520586http://www.mandriva.com/security/advisories?name=MDVSA-2008:107http://www.openssl.org/news/secadv_20080528.txthttp://www.securityfocus.com/archive/1/492932/100/0/threadedhttp://www.securityfocus.com/bid/29405http://www.securitytracker.com/id?1020122http://www.ubuntu.com/usn/usn-620-1http://www.vupen.com/english/advisories/2008/1680http://www.vupen.com/english/advisories/2008/1937/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42667https://www.redhat.com/archives/fedora-package-announce/2008-May/msg01029.html
2008-05-29
Published