OpenSSL Multiple Denial of Service Vulnerabilities
BID:29405
Info
OpenSSL Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 29405 |
| Class: | Unknown |
| CVE: |
CVE-2008-0891 CVE-2008-1672 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2008 12:00AM |
| Updated: | Apr 13 2015 10:25PM |
| Credit: | Codenomicon |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current rPath rPath Linux 2 OpenSSL Project OpenSSL 0.9.8g OpenSSL Project OpenSSL 0.9.8 f Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service 0 Nortel Networks Media Processing Svr 500 Rel 3.0 Nortel Networks Media Processing Svr 1000 Rel 3.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Gentoo Linux cwRsync cwRsync 2.1.3 cwRsync cwRsync 2.1.2 cwRsync cwRsync 2.1.1 cwRsync cwRsync 2.1 cwRsync cwRsync 2.0.10 cwRsync cwRsync 2.0.9 |
| Not Vulnerable: |
OpenSSL Project OpenSSL 0.9.8 h cwRsync cwRsync 2.1.4 |
Discussion
OpenSSL Multiple Denial of Service Vulnerabilities
OpenSSL is prone to multiple denial-of-service vulnerabilities.
Attackers can leverage these issues to cause a client or server application to crash. Successful exploits will deny service to legitimate users.
OpenSSL 0.9.8f and 0.9.8g are reported vulnerable. Other versions may be affected as well.
OpenSSL is prone to multiple denial-of-service vulnerabilities.
Attackers can leverage these issues to cause a client or server application to crash. Successful exploits will deny service to legitimate users.
OpenSSL 0.9.8f and 0.9.8g are reported vulnerable. Other versions may be affected as well.
Exploit / POC
OpenSSL Multiple Denial of Service Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSSL Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
OpenSSL Project OpenSSL 0.9.8 f
OpenSSL Project OpenSSL 0.9.8g
Solution:
Updates are available. Please see the references for more information.
OpenSSL Project OpenSSL 0.9.8 f
-
OpenSSL Project openssl-0.9.8h.tar.gz
http://www.openssl.org/source/openssl-0.9.8h.tar.gz
OpenSSL Project OpenSSL 0.9.8g
-
OpenSSL Project openssl-0.9.8h.tar.gz
http://www.openssl.org/source/openssl-0.9.8h.tar.gz
References
OpenSSL Multiple Denial of Service Vulnerabilities
References:
References:
- cwRsync Release Name: 2.1.4 (cwRsync)
- OpenSSL Project (OpenSSL Project)
- Vulnerability Note VU#661475 (US-CERT)
- Vulnerability Advisory on OpenSSL ([email protected] )
- CERT-FI Vulnerability Advisory on OpenSSL (CERT-FI)
- Nortel Response to 2 Potential DoS Vulnerabilities in OpenSS (Nortel Networks)
- Nortel Response to 2 Potential DoS Vulnerabilities in OpenSSL Rev 2 (Nortel)
- Nortel Response to 2 Potential DoS Vulnerabilities in OpenSSL Rev 3 (Nortel Networks)
- OpenSSL Security Advisory [28-Mar-2008] (OpenSSL Project)
- Vulnerability Note VU#520586 (US-CERT )