OpenSSL SSLv2 Client_Master_Key Remote Denial Of Service Vulnerability
BID:8746
Info
OpenSSL SSLv2 Client_Master_Key Remote Denial Of Service Vulnerability
| Bugtraq ID: | 8746 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1568 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2003 12:00AM |
| Updated: | Mar 19 2015 09:04AM |
| Credit: | Discovery of this vulnerability has been credited to Patrik Hornik <[email protected]>. |
| Vulnerable: |
Redhat openssl096-0.9.6-6.i386.rpm Redhat openssl096-0.9.6-11.i386.rpm Redhat openssl095a-0.9.5a-16.i386.rpm Redhat openssl095a-0.9.5a-11.i386.rpm Redhat openssl-python-0.9.6-3.i386.rpm Redhat openssl-python-0.9.5a-14.i386.rpm Redhat openssl-perl-0.9.6b-8.i386.rpm Redhat openssl-perl-0.9.6b-29.i386.rpm Redhat openssl-perl-0.9.6b-18.i386.rpm Redhat openssl-perl-0.9.6-3.i386.rpm Redhat openssl-perl-0.9.5a-14.i386.rpm Redhat openssl-devel-0.9.6b-8.i386.rpm Redhat openssl-devel-0.9.6b-29.i386.rpm Redhat openssl-devel-0.9.6b-18.i386.rpm Redhat openssl-devel-0.9.6-3.i386.rpm Redhat openssl-devel-0.9.5a-14.i386.rpm Redhat openssl-0.9.6b-8.i386.rpm Redhat openssl-0.9.6b-29.i386.rpm Redhat openssl-0.9.6b-18.i386.rpm Redhat openssl-0.9.6-3.i386.rpm Redhat openssl-0.9.5a-14.i386.rpm OpenSSL Project OpenSSL 0.9.6 e OpenSSL Project OpenSSL 0.9.6 d OpenSSL Project OpenSSL 0.9.6 c OpenSSL Project OpenSSL 0.9.6 b OpenSSL Project OpenSSL 0.9.6 a OpenSSL Project OpenSSL 0.9.6 OpenSSL Project OpenSSL 0.9.5 a OpenSSL Project OpenSSL 0.9.5 OpenSSL Project OpenSSL 0.9.4 OpenSSL Project OpenSSL 0.9.3 OpenSSL Project OpenSSL 0.9.2 b OpenSSL Project OpenSSL 0.9.1 c IBM HTTP Server 1.3.28 IBM HTTP Server 1.3.26 .2 IBM HTTP Server 1.3.26 .1 IBM HTTP Server 1.3.26 IBM HTTP Server 1.3.19 .5 IBM HTTP Server 1.3.19 .4 IBM HTTP Server 1.3.19 .3 IBM HTTP Server 1.3.19 .2 IBM HTTP Server 1.3.19 .1 IBM HTTP Server 1.3.19 IBM HTTP Server 1.3.12 .7 IBM HTTP Server 1.3.12 .6 IBM HTTP Server 1.3.12 .5 IBM HTTP Server 1.3.12 .4 IBM HTTP Server 1.3.12 .3 IBM HTTP Server 1.3.12 .2 IBM HTTP Server 1.3.12 .1 IBM HTTP Server 1.3.12 |
| Not Vulnerable: |
OpenSSL Project OpenSSL 0.9.7 c OpenSSL Project OpenSSL 0.9.7 beta3 OpenSSL Project OpenSSL 0.9.7 beta2 OpenSSL Project OpenSSL 0.9.7 beta1 OpenSSL Project OpenSSL 0.9.7 b OpenSSL Project OpenSSL 0.9.7 a OpenSSL Project OpenSSL 0.9.7 OpenSSL Project OpenSSL 0.9.6 k OpenSSL Project OpenSSL 0.9.6 j OpenSSL Project OpenSSL 0.9.6 i OpenSSL Project OpenSSL 0.9.6 h OpenSSL Project OpenSSL 0.9.6 g OpenSSL Project OpenSSL 0.9.6 f |
Discussion
OpenSSL SSLv2 Client_Master_Key Remote Denial Of Service Vulnerability
OpenSSL SSLv2 has been reported prone to a remotely triggered denial of service when processing a specially crafted malicious CLIENT_MASTER_KEY message.
It has been reported that a remote attacker may use a maliciously crafted CLIENT_MASTER_KEY message to influence the execution flow of a vulnerable service implmenting SSLv2 into a die() procedure. This will effectively cause the affected process to abort, denying service to legitimate users.
This vulnerability is not reported to be present in OpenSSL versions greater than 0.9.6f of the 0.9.6 series of releases, because the use of the die() procedure is no longer implemented. It is not known whether the 0.9.7 series is also affected.
OpenSSL SSLv2 has been reported prone to a remotely triggered denial of service when processing a specially crafted malicious CLIENT_MASTER_KEY message.
It has been reported that a remote attacker may use a maliciously crafted CLIENT_MASTER_KEY message to influence the execution flow of a vulnerable service implmenting SSLv2 into a die() procedure. This will effectively cause the affected process to abort, denying service to legitimate users.
This vulnerability is not reported to be present in OpenSSL versions greater than 0.9.6f of the 0.9.6 series of releases, because the use of the die() procedure is no longer implemented. It is not known whether the 0.9.7 series is also affected.
Exploit / POC
OpenSSL SSLv2 Client_Master_Key Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenSSL SSLv2 Client_Master_Key Remote Denial Of Service Vulnerability
Solution:
OpenSSL have reportedly addressed this issue in versions 0.9.6f and greater.
Red Hat has reportedly addressed this issue in the RHSA-2003:291-11 advisory. See referenced advisory for further information relating to obtaining and applying fixes.
Guardian Digital has released an advisory for EnGarde (ESA-20031003-028) to address this issue. Updates may be applied with the Guardian Digital WebTool. Further details may be found in the attached advisory.
VMware has released fixes to address this issue. Please see the related web reference for more information.
IBM has released fixes to address these issues in IBM HTTP Server.
OpenSSL Project OpenSSL 0.9.6 d
OpenSSL Project OpenSSL 0.9.6 c
OpenSSL Project OpenSSL 0.9.6
OpenSSL Project OpenSSL 0.9.6 b
OpenSSL Project OpenSSL 0.9.6 e
OpenSSL Project OpenSSL 0.9.6 a
IBM HTTP Server 1.3.12 .7
IBM HTTP Server 1.3.12 .2
IBM HTTP Server 1.3.12 .6
IBM HTTP Server 1.3.12 .1
IBM HTTP Server 1.3.12 .3
IBM HTTP Server 1.3.12
IBM HTTP Server 1.3.12 .5
IBM HTTP Server 1.3.12 .4
IBM HTTP Server 1.3.19 .1
IBM HTTP Server 1.3.19 .3
IBM HTTP Server 1.3.19 .4
IBM HTTP Server 1.3.19
IBM HTTP Server 1.3.19 .5
IBM HTTP Server 1.3.19 .2
IBM HTTP Server 1.3.26
IBM HTTP Server 1.3.26 .2
IBM HTTP Server 1.3.26 .1
IBM HTTP Server 1.3.28
Solution:
OpenSSL have reportedly addressed this issue in versions 0.9.6f and greater.
Red Hat has reportedly addressed this issue in the RHSA-2003:291-11 advisory. See referenced advisory for further information relating to obtaining and applying fixes.
Guardian Digital has released an advisory for EnGarde (ESA-20031003-028) to address this issue. Updates may be applied with the Guardian Digital WebTool. Further details may be found in the attached advisory.
VMware has released fixes to address this issue. Please see the related web reference for more information.
IBM has released fixes to address these issues in IBM HTTP Server.
OpenSSL Project OpenSSL 0.9.6 d
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 c
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6
-
Engarde Secure Linux openssl-0.9.6-1.0.21.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-0.9.6-1.0.21.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-devel-0.9.6-1.0.21.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-devel-0.9.6-1.0.21.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-misc-0.9.6-1.0.21.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-misc-0.9.6-1.0.21.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 b
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 e
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 a
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
IBM HTTP Server 1.3.12 .7
IBM HTTP Server 1.3.12 .2
IBM HTTP Server 1.3.12 .6
IBM HTTP Server 1.3.12 .1
IBM HTTP Server 1.3.12 .3
IBM HTTP Server 1.3.12
IBM HTTP Server 1.3.12 .5
IBM HTTP Server 1.3.12 .4
IBM HTTP Server 1.3.19 .1
IBM HTTP Server 1.3.19 .3
IBM HTTP Server 1.3.19 .4
IBM HTTP Server 1.3.19
IBM HTTP Server 1.3.19 .5
IBM HTTP Server 1.3.19 .2
IBM HTTP Server 1.3.26
IBM HTTP Server 1.3.26 .2
IBM HTTP Server 1.3.26 .1
IBM HTTP Server 1.3.28
References
OpenSSL SSLv2 Client_Master_Key Remote Denial Of Service Vulnerability
References:
References:
- ESX OpenSSL updates (VMware)
- GSX OpenSSL updates (VMware)
- RHSA-2003:291-11 (RedHat)
- New OpenSSL remote vulnerability (issue date 2003/10/02) (Patrik Hornik
)