OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
BID:5361
Info
OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
| Bugtraq ID: | 5361 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0657 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovery of this issue credited to A.L. Digital Ltd and The Bunker. |
| Vulnerable: |
Sun Crypto Accelerator 1000 OpenSSL Project OpenSSL 0.9.7 beta2 OpenSSL Project OpenSSL 0.9.7 beta1 Novell NetMail 3.10 d Novell NetMail 3.10 c Novell NetMail 3.10 b Novell NetMail 3.10 a Novell NetMail 3.10 HP Webproxy 2.0 HP Webproxy 1.0 HP VirtualVault 4.6 HP VirtualVault 4.5 HP Tru64 UNIX INTERNET EXPRESS 5.9 HP Tru64 UNIX Compaq Secure Web Server 5.8.1 HP TCP/IP Services for OpenVMS 5.3 HP OpenVMS Secure Web Server 1.2 HP OpenVMS Secure Web Server 1.1 -1 HP INTERNET EXPRESS EAK 2.0 HP HP-UX 11.22 HP HP-UX 11.20 HP HP-UX 11.11 HP HP-UX 11.0 |
| Not Vulnerable: |
OpenSSL Project OpenSSL 0.9.7 beta3 Novell NetMail 3.10 e |
Exploit / POC
OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
Solution:
A patch has been made by Ben Laurie <[email protected]>. It should be noted that this patch has not been thoroughly tested.
HP has made fixes available in the form of upgrade packages. Packages are available at http://www.software.hp.com/ISS_products_list.html, and are binary versions of Apache 1.3.26.05 and 2.0.39.05 respectively.
Sun has stated that the Crypto Accelerator 1000 board is vulnerable to this issue. A patch (112869-02) is available for download.
Sun has a new patch available for download. The patch, 113355-01, is for Crypto Accelerator 1000 1.1 board for Solaris 8 or 9.
Sun Crypto Accelerator 1000
OpenSSL Project OpenSSL 0.9.7 beta2
OpenSSL Project OpenSSL 0.9.7 beta1
HP Webproxy 1.0
HP Webproxy 2.0
Novell NetMail 3.10
Novell NetMail 3.10 b
Novell NetMail 3.10 c
Novell NetMail 3.10 a
Novell NetMail 3.10 d
HP VirtualVault 4.5
HP VirtualVault 4.6
Solution:
A patch has been made by Ben Laurie <[email protected]>. It should be noted that this patch has not been thoroughly tested.
HP has made fixes available in the form of upgrade packages. Packages are available at http://www.software.hp.com/ISS_products_list.html, and are binary versions of Apache 1.3.26.05 and 2.0.39.05 respectively.
Sun has stated that the Crypto Accelerator 1000 board is vulnerable to this issue. A patch (112869-02) is available for download.
Sun has a new patch available for download. The patch, 113355-01, is for Crypto Accelerator 1000 1.1 board for Solaris 8 or 9.
Sun Crypto Accelerator 1000
-
Sun 112869-02
Sun Crypto Accelerator 1000 1.0 (for Solaris 8)
http://sunsolve.sun.com/pub-cgi/patchDownload.pl?target=112869&method= f -
Sun 113355-01
Sun Crypto Accelerator 1000 1.1 (for Solaris 8 and 9)
http://sunsolve.sun.com/pub-cgi/patchDownload.pl?target=113355&method= f
OpenSSL Project OpenSSL 0.9.7 beta2
-
Ben Laurie openssl-0.9.7-sec.patch
Submitted by Ben Laurie.
http://downloads.securityfocus.com/vulnerabilities/patches/openssl-0.9 .7-sec.patch
OpenSSL Project OpenSSL 0.9.7 beta1
-
Ben Laurie openssl-0.9.7-sec.patch
Submitted by Ben Laurie.
http://downloads.securityfocus.com/vulnerabilities/patches/openssl-0.9 .7-sec.patch
HP Webproxy 1.0
-
HP PHSS_27655
http://itrc.hp.com
HP Webproxy 2.0
-
HP PHSS_27656
http://itrc.hp.com
Novell NetMail 3.10
-
Novell netmail310e.zip
http://support.novell.com/servlet/filedownload/pub/netmail310e.zip
Novell NetMail 3.10 b
-
Novell netmail310e.zip
http://support.novell.com/servlet/filedownload/pub/netmail310e.zip
Novell NetMail 3.10 c
-
Novell netmail310e.zip
http://support.novell.com/servlet/filedownload/pub/netmail310e.zip
Novell NetMail 3.10 a
-
Novell netmail310e.zip
http://support.novell.com/servlet/filedownload/pub/netmail310e.zip
Novell NetMail 3.10 d
-
Novell netmail310e.zip
http://support.novell.com/servlet/filedownload/pub/netmail310e.zip
HP VirtualVault 4.5
-
HP PHSS_27477
http://itrc.hp.com -
HP PHSS_27627
http://itrc.hp.com
HP VirtualVault 4.6
-
HP PHSS_27263
http://itrc.hp.com -
HP PHSS_27423
http://itrc.hp.com -
HP PHSS_27476
http://itrc.hp.com -
HP PHSS_27637
http://itrc.hp.com
References
OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
References:
References:
- NetMail 3.1e Update for NetWare (Novell)
- OpenSSL Security Advisory [30 July 2002] (OpenSSL Project)
- Security Patch Downloads (Sun Microsystems)