CVE-2008-1672NULL Pointer Dereference in Openssl

Severity
4.3MEDIUMNVD
EPSS
19.0%
top 4.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 29
Latest updateFeb 29

Description

OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/openssl< openssl 0.9.8g-10.1 (bookworm)
Debianopenssl/openssl< 0.9.8g-10.1+3
NVDopenssl/openssl0.9.8f, 0.9.8g+1

Also affects: Ubuntu Linux 8.04

Patches

🔴Vulnerability Details

2
GHSA
GHSA-322g-pxmj-97cc: OpenSSL 02022-05-01
OSV
CVE-2008-1672: OpenSSL 02008-05-29

📋Vendor Advisories

3
Ubuntu
OpenSSL vulnerabilities2008-06-26
Red Hat
openssl: Omit Server Key Exchange message crash2008-05-28
Debian
CVE-2008-1672: openssl - OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (...2008

📄Research Papers

1
arXiv
CEBin: A Cost-Effective Framework for Large-Scale Binary Code Similarity Detection2024-02-29

💬Community

1
Bugzilla
CVE-2008-1672 openssl: Omit Server Key Exchange message crash2008-05-27