CVE-2008-1678
published 2008-07-10CVE-2008-1678: Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.29%
91.7th percentile
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | apache2 | < apache2 2.2.8-4 (bookworm) | apache2 2.2.8-4 (bookworm) |
| debian | openssl | < openssl 0.9.8k-8 (bookworm) | openssl 0.9.8k-8 (bookworm) |
| openssl | openssl | <= 0.9.8l | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openssl significant memory leak in certain SSLv3 requests (DoS)
vendor_redhat·2010-01-13·CVSS 5.0
CVE-2009-4355 [MEDIUM] CWE-401 openssl significant memory leak in certain SSLv3 requests (DoS)
openssl significant memory leak in certain SSLv3 requests (DoS)
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-03-10·CVSS 4.3
CVE-2007-6203 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the method specifier header from
an HTTP request when it is returned in an error message, which could result in
browsers becoming vulnerable to cross-site scripting attacks when processing the
output. With cross-site scripting vulnerabilities, if a user were tricked into
viewing server output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain. This issue only affected Ubuntu 6.06 LTS and
7.10. (CVE-2007-6203)
It was discovered that Apache was vulnerable to a cross-site request forgery
(CSRF) in the mod_proxy_balancer balancer manager. If an Apache administrator
were t
Debian
CVE-2009-4355: openssl - Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in Open...
vendor_debian·2009·CVSS 5.0
CVE-2009-4355 [MEDIUM] CVE-2009-4355: openssl - Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in Open...
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
Scope: local
bookworm: resolved (fixed in 0.9.8k-8)
bullseye: resolved (fixed in 0.9.8k-8)
forky: resolved (fixed in 0.9.8k-8)
sid: resolved (fixed in 0.9.8k-8)
trixie: resolved (fixed in 0.9.8k-8)
Red Hat
httpd: mod_ssl per-connection memory leak for connections with zlib compression
vendor_redhat·2008-04-30·CVSS 5.0
CVE-2008-1678 [MEDIUM] CWE-401 httpd: mod_ssl per-connection memory leak for connections with zlib compression
httpd: mod_ssl per-connection memory leak for connections with zlib compression
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Statement: Not vulnerable. This issue did not affect the versions of mod_ssl or httpd as shipped with Red Hat Enterprise Linux 2.1, 3, 4, and 5 prior to 5.3.
Debian
CVE-2008-1678: apache2 - Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl...
vendor_debian·2008·CVSS 5.0
CVE-2008-1678 [MEDIUM] CVE-2008-1678: apache2 - Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl...
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Scope: local
bookworm: resolved (fixed in 2.2.8-4)
bullseye: resolved (fixed in 2.2.8-4)
forky: resolved (fixed in 2.2.8-4)
sid: resolved (fixed in 2.2.8-4)
trixie: resolved (fixed in 2.2.8-4)
GHSA
GHSA-cg3r-vf2p-3f9h: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-4355 [MEDIUM] GHSA-cg3r-vf2p-3f9h: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
GHSA
GHSA-xwx3-pfr8-5rp4: Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib
ghsa_unreviewed·2022-05-01
CVE-2008-1678 [MEDIUM] GHSA-xwx3-pfr8-5rp4: Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
OSV
CVE-2009-4355: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
osv·2010-01-14·CVSS 5.0
CVE-2009-4355 [MEDIUM] CVE-2009-4355: Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
OSV
CVE-2008-1678: Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib
osv·2008-07-10·CVSS 5.0
CVE-2008-1678 [MEDIUM] CVE-2008-1678: Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-4355 openssl significant memory leak in certain SSLv3 requests (DoS)
bugzilla·2009-12-11·CVSS 5.0
CVE-2009-4355 [MEDIUM] CVE-2009-4355 openssl significant memory leak in certain SSLv3 requests (DoS)
CVE-2009-4355 openssl significant memory leak in certain SSLv3 requests (DoS)
rPath has had a report of a Denial of Service attack which we have reproduced on Red Hat Enterprise Linux 5 with the latest affected components installed.
Description of problem:
When the php module is enabled, after apache receives a "graceful" (USR1) signal, every SSLv3 request leaks a significant amount of memory (hundreds of KB).
Version-Release number of selected component (if applicable):
# rpm -q php httpd mod_ssl openssl
php-5.1.6-23.2.el5_3
httpd-2.2.3-31.el5_4.2
mod_ssl-2.2.3-31.el5_4.2
openssl-0.9.8e-12.el5
How reproducible:
Reliably
Steps to Reproduce:
1. Install mentioned components
2. service httpd start
3. note that memory utilization is stable for httpd
4. start a request loop:
while :; do cu
Bugzilla
CVE-2008-1678 httpd: mod_ssl per-connection memory leak for connections with zlib compression
bugzilla·2008-05-19·CVSS 5.0
CVE-2008-1678 [MEDIUM] CVE-2008-1678 httpd: mod_ssl per-connection memory leak for connections with zlib compression
CVE-2008-1678 httpd: mod_ssl per-connection memory leak for connections with zlib compression
Apache httpd web server's mod_ssl module linked against OpenSSL >= 0.9.8f can
leak pre-connection memory when connecting client reports support for a
compression algorithm in the initial handshake, causing httpd to run out of
memory after certain amount of SSL connections.
Upstream and Ubuntu bug reports:
https://issues.apache.org/bugzilla/show_bug.cgi?id=44975
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/224945
Upstream fix:
http://svn.apache.org/viewvc?view=rev&revision=654119
Discussion:
According to Joe Orton's investigation, this issue was introduced by the
following OpenSSL patch:
http://cvs.openssl.org/chngview?cn=15897
which was first included in OpenSSL 0.9.8e.
This issu
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://bugs.gentoo.org/show_bug.cgi?id=222643http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://marc.info/?l=openssl-dev&m=121060672602371&w=2http://secunia.com/advisories/31026http://secunia.com/advisories/31416http://secunia.com/advisories/32222http://secunia.com/advisories/34219http://secunia.com/advisories/35264http://secunia.com/advisories/38761http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://secunia.com/advisories/44183http://security.gentoo.org/glsa/glsa-200807-06.xmlhttp://securityreason.com/securityalert/3981http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049http://support.apple.com/kb/HT3216http://svn.apache.org/viewvc?view=rev&revision=654119http://www.mandriva.com/security/advisories?name=MDVSA-2009:124http://www.redhat.com/support/errata/RHSA-2009-1075.htmlhttp://www.securityfocus.com/bid/31681http://www.securityfocus.com/bid/31692http://www.ubuntu.com/usn/USN-731-1http://www.vupen.com/english/advisories/2008/2780https://bugs.edge.launchpad.net/bugs/186339https://bugs.edge.launchpad.net/bugs/224945https://bugzilla.redhat.com/show_bug.cgi?id=447268https://exchange.xforce.ibmcloud.com/vulnerabilities/43948https://issues.apache.org/bugzilla/show_bug.cgi?id=44975https://kb.bluecoat.com/index?page=content&id=SA50https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9754https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=222643http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.htmlhttp://marc.info/?l=openssl-dev&m=121060672602371&w=2http://secunia.com/advisories/31026http://secunia.com/advisories/31416http://secunia.com/advisories/32222http://secunia.com/advisories/34219http://secunia.com/advisories/35264http://secunia.com/advisories/38761http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://secunia.com/advisories/44183http://security.gentoo.org/glsa/glsa-200807-06.xmlhttp://securityreason.com/securityalert/3981http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049http://support.apple.com/kb/HT3216http://svn.apache.org/viewvc?view=rev&revision=654119http://www.mandriva.com/security/advisories?name=MDVSA-2009:124http://www.redhat.com/support/errata/RHSA-2009-1075.htmlhttp://www.securityfocus.com/bid/31681http://www.securityfocus.com/bid/31692http://www.ubuntu.com/usn/USN-731-1http://www.vupen.com/english/advisories/2008/2780https://bugs.edge.launchpad.net/bugs/186339https://bugs.edge.launchpad.net/bugs/224945https://bugzilla.redhat.com/show_bug.cgi?id=447268https://exchange.xforce.ibmcloud.com/vulnerabilities/43948https://issues.apache.org/bugzilla/show_bug.cgi?id=44975https://kb.bluecoat.com/index?page=content&id=SA50https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9754https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.html
2008-07-10
Published