OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability
BID:8970
Info
OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability
| Bugtraq ID: | 8970 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0851 CVE-2003-0851 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2003 12:00AM |
| Updated: | Mar 19 2015 08:52AM |
| Credit: | Discovery credited to Novell. |
| Vulnerable: |
SGI IRIX 6.5.21 m SGI IRIX 6.5.21 f SGI IRIX 6.5.20 m SGI IRIX 6.5.20 f SGI IRIX 6.5.19 m SGI IRIX 6.5.19 f RedHat Linux 8.0 RedHat Linux 7.3 RedHat Linux 7.2 Opera Software Opera Web Browser 7.22 Opera Software Opera Web Browser 7.21 Opera Software Opera Web Browser 7.20 OpenSSL Project OpenSSL 0.9.7 b OpenSSL Project OpenSSL 0.9.7 a OpenSSL Project OpenSSL 0.9.7 OpenSSL Project OpenSSL 0.9.6 k OpenSSL Project OpenSSL 0.9.6 j OpenSSL Project OpenSSL 0.9.6 i OpenSSL Project OpenSSL 0.9.6 h OpenSSL Project OpenSSL 0.9.6 g OpenSSL Project OpenSSL 0.9.6 f OpenSSL Project OpenSSL 0.9.6 e OpenSSL Project OpenSSL 0.9.6 d OpenSSL Project OpenSSL 0.9.6 c OpenSSL Project OpenSSL 0.9.6 b OpenSSL Project OpenSSL 0.9.6 a OpenSSL Project OpenSSL 0.9.6 OpenSSL Project OpenSSL 0.9.5 a OpenSSL Project OpenSSL 0.9.5 OpenSSL Project OpenSSL 0.9.4 OpenSSL Project OpenSSL 0.9.3 OpenSSL Project OpenSSL 0.9.2 b OpenSSL Project OpenSSL 0.9.1 c NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 Cisco PIX Firewall 6.3 (1) Cisco PIX Firewall 6.2.2 .111 Cisco PIX Firewall 6.2.2 Cisco PIX Firewall 6.2.1 Cisco PIX Firewall 6.2 (3) Cisco PIX Firewall 6.2 (2) Cisco PIX Firewall 6.2 (1) Cisco PIX Firewall 6.2 Cisco PIX Firewall 6.1.4 Cisco PIX Firewall 6.1.3 Cisco PIX Firewall 6.1 (5) Cisco PIX Firewall 6.1 (4) Cisco PIX Firewall 6.1 (3) Cisco PIX Firewall 6.1 (2) Cisco PIX Firewall 6.1 (1) Cisco PIX Firewall 6.1 Cisco PIX Firewall 6.0.4 Cisco PIX Firewall 6.0.3 Cisco PIX Firewall 6.0 (4.101) Cisco PIX Firewall 6.0 (4) Cisco PIX Firewall 6.0 (2) Cisco PIX Firewall 6.0 (1) Cisco PIX Firewall 6.0 Cisco IOS 12.2SY Cisco IOS 12.2SX Cisco IOS 12.1(11b)E12 Cisco IOS 12.1(11b)E Cisco IOS 12.1(11)EC Cisco IOS 12.1(11)EA1 Cisco IOS 12.1(11)E Cisco Firewall Services Module (FWSM) 2.1 (0.208) Cisco CSS11000 Content Services Switch |
| Not Vulnerable: |
Opera Software Opera Web Browser 7.23 OpenSSL Project OpenSSL 0.9.7 c OpenSSL Project OpenSSL 0.9.6 l Blue Coat Systems Security Gateway OS 3.1.2 Blue Coat Systems Security Gateway OS 2.1.10 Blue Coat Systems CacheOS CA/SA 4.1.12 |
Discussion
OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability
A problem has been identified in OpenSSL when handling specific types of ASN.1 requests. This may result in remote attackers creating a denial of service condition.
This issue is also known to affect numerous Cisco products. It is possible that other vendors will also be acknowledging this issue and providing fixes.
A problem has been identified in OpenSSL when handling specific types of ASN.1 requests. This may result in remote attackers creating a denial of service condition.
This issue is also known to affect numerous Cisco products. It is possible that other vendors will also be acknowledging this issue and providing fixes.
Exploit / POC
OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability
Solution:
Fixes have been made available by the vendor.
Opera have released a new version of their Internet browser; this version 7.23 includes a patch to address this vulnerability. See attached changelog for further detail.
Cisco has released a revision of their SSL Implementation Vulnerabilities advisory (ID:45643) to include information about products that are affected by this vulnerability and workaround/fix information, additionally Cisco have released software availability dates. Please see the attached advisory for further details about which products are vulnerable and how to obtain fixes. This BID will be updated as Cisco provides more complete information about affected products and fixes.
Guardian Digitial has released security advisory ESA-20031104-029 to address this issue. Affected users are advised to run the webtool to update systems.
BlueCoat Systems has released an advisory stating that it has identified the vulnerability in versions of SGOS prior to 3.1.2 and 2.1.10, as well as CA/SA prior to 4.1.12. Fixed versions are currently in development.
SGI has also released an advisory 20030904-02-P that includes patches which address this issue.
NetBSD has released an advisory that includes updates. Fix details may be found in the attached advisory.
Red Hat advisory RHSA-2004:119-04 was also released for Red Hat Linux Enterprise releases. Please see the attached advisory for further details. Enterprise fixes may be obtained through the Red Hat Network.
RedHat has released an advisory RHSA-2004:139-05 to address this and other issues. Please see the advisory in web references for more information.
RedHat has released Fedora advisory FEDORA-2004-095 dealing with the issues and others. Please see the advisory section for more details.
RedHat has released an advisory RHSA-2004:119-04 to address this and other issues. Please see the advisory in web references for more information.
Fedora advisory FEDORA-2005-1042 is available to address this and other issues in Fedora Core 3. Please see the referenced advisory for more information.
OpenSSL Project OpenSSL 0.9.1 c
OpenSSL Project OpenSSL 0.9.2 b
OpenSSL Project OpenSSL 0.9.3
OpenSSL Project OpenSSL 0.9.4
OpenSSL Project OpenSSL 0.9.5 a
OpenSSL Project OpenSSL 0.9.5
OpenSSL Project OpenSSL 0.9.6 j
OpenSSL Project OpenSSL 0.9.6 d
OpenSSL Project OpenSSL 0.9.6 c
OpenSSL Project OpenSSL 0.9.6 e
OpenSSL Project OpenSSL 0.9.6 h
OpenSSL Project OpenSSL 0.9.6 a
OpenSSL Project OpenSSL 0.9.6 f
OpenSSL Project OpenSSL 0.9.6
OpenSSL Project OpenSSL 0.9.6 b
OpenSSL Project OpenSSL 0.9.6 g
OpenSSL Project OpenSSL 0.9.6 k
OpenSSL Project OpenSSL 0.9.6 i
OpenSSL Project OpenSSL 0.9.7 a
OpenSSL Project OpenSSL 0.9.7 b
SGI IRIX 6.5.19 m
SGI IRIX 6.5.19 f
SGI IRIX 6.5.20 f
SGI IRIX 6.5.20 m
SGI IRIX 6.5.21 m
SGI IRIX 6.5.21 f
Opera Software Opera Web Browser 7.20
Opera Software Opera Web Browser 7.21
Opera Software Opera Web Browser 7.22
Solution:
Fixes have been made available by the vendor.
Opera have released a new version of their Internet browser; this version 7.23 includes a patch to address this vulnerability. See attached changelog for further detail.
Cisco has released a revision of their SSL Implementation Vulnerabilities advisory (ID:45643) to include information about products that are affected by this vulnerability and workaround/fix information, additionally Cisco have released software availability dates. Please see the attached advisory for further details about which products are vulnerable and how to obtain fixes. This BID will be updated as Cisco provides more complete information about affected products and fixes.
Guardian Digitial has released security advisory ESA-20031104-029 to address this issue. Affected users are advised to run the webtool to update systems.
BlueCoat Systems has released an advisory stating that it has identified the vulnerability in versions of SGOS prior to 3.1.2 and 2.1.10, as well as CA/SA prior to 4.1.12. Fixed versions are currently in development.
SGI has also released an advisory 20030904-02-P that includes patches which address this issue.
NetBSD has released an advisory that includes updates. Fix details may be found in the attached advisory.
Red Hat advisory RHSA-2004:119-04 was also released for Red Hat Linux Enterprise releases. Please see the attached advisory for further details. Enterprise fixes may be obtained through the Red Hat Network.
RedHat has released an advisory RHSA-2004:139-05 to address this and other issues. Please see the advisory in web references for more information.
RedHat has released Fedora advisory FEDORA-2004-095 dealing with the issues and others. Please see the advisory section for more details.
RedHat has released an advisory RHSA-2004:119-04 to address this and other issues. Please see the advisory in web references for more information.
Fedora advisory FEDORA-2005-1042 is available to address this and other issues in Fedora Core 3. Please see the referenced advisory for more information.
OpenSSL Project OpenSSL 0.9.1 c
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.2 b
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.3
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.4
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.5 a
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.5
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 j
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 d
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 c
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 e
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 h
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 a
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 f
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6
-
Engarde Secure Linux openssl-0.9.6-1.0.22.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-0.9.6-1.0.22.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-devel-0.9.6-1.0.22.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-devel-0.9.6-1.0.22.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-misc-0.9.6-1.0.22.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-misc-0.9.6-1.0.22.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Fedora openssl096-0.9.6-26.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /openssl096-0.9.6-26.i386.rpm -
Fedora openssl096-0.9.6-26.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/openssl096-0.9.6-26.x86_64.rpm -
Fedora openssl096-debuginfo-0.9.6-26.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/openssl096-debuginfo-0.9.6-26.i386.rpm -
Fedora openssl096-debuginfo-0.9.6-26.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/debug/openssl096-debuginfo-0.9.6-26.x86_64.rpm -
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 b
-
Fedora openssl096b-0.9.6b-18.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /openssl096b-0.9.6b-18.i386.rpm -
Fedora openssl096b-0.9.6b-18.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/openssl096b-0.9.6b-18.x86_64.rpm -
Fedora openssl096b-debuginfo-0.9.6b-18.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/openssl096b-debuginfo-0.9.6b-18.i386.rpm -
Fedora openssl096b-debuginfo-0.9.6b-18.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/debug/openssl096b-debuginfo-0.9.6b-18.x86_64.rpm -
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 g
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 k
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 i
-
OpenSSL Project openssl-0.9.6l.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.7 a
-
Fedora openssl-0.9.7a-33.10.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /openssl-0.9.7a-33.10.i386.rpm -
Fedora openssl-0.9.7a-33.10.i686.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /openssl-0.9.7a-33.10.i686.rpm -
Fedora openssl-0.9.7a-33.10.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/openssl-0.9.7a-33.10.x86_64.rpm -
Fedora openssl-debuginfo-0.9.7a-33.10.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/openssl-debuginfo-0.9.7a-33.10.i386.rpm -
Fedora openssl-debuginfo-0.9.7a-33.10.i686.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/openssl-debuginfo-0.9.7a-33.10.i686.rpm -
Fedora openssl-debuginfo-0.9.7a-33.10.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/debug/openssl-debuginfo-0.9.7a-33.10.x86_64.rpm -
Fedora openssl-devel-0.9.7a-33.10.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /openssl-devel-0.9.7a-33.10.i386.rpm -
Fedora openssl-devel-0.9.7a-33.10.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/openssl-devel-0.9.7a-33.10.x86_64.rpm -
Fedora openssl-perl-0.9.7a-33.10.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /openssl-perl-0.9.7a-33.10.i386.rpm -
Fedora openssl-perl-0.9.7a-33.10.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/openssl-perl-0.9.7a-33.10.x86_64.rpm -
OpenSSL Project openssl-0.9.7c.tar.gz
ftp://ftp.openssl.org/source/
OpenSSL Project OpenSSL 0.9.7 b
-
OpenSSL Project openssl-0.9.7c.tar.gz
ftp://ftp.openssl.org/source/
SGI IRIX 6.5.19 m
SGI IRIX 6.5.19 f
SGI IRIX 6.5.20 f
SGI IRIX 6.5.20 m
SGI IRIX 6.5.21 m
SGI IRIX 6.5.21 f
Opera Software Opera Web Browser 7.20
-
Opera Software Opera 7.23 for Windows
http://www.opera.com/download/
Opera Software Opera Web Browser 7.21
-
Opera Software Opera 7.23 for Windows
http://www.opera.com/download/
Opera Software Opera Web Browser 7.22
-
Opera Software Opera 7.23 for Windows
http://www.opera.com/download/
References
OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability
References:
References:
- Changelog for Opera 7.23 for Windows (Opera Software)
- Cisco Security Advisory: SSL Implementation Vulnerabilities (Cisco)
- OpenSSL Security Advisory [4 November 2003] (OpenSSL Project)
- RHSA-2004:119-04 - Updated OpenSSL packages fix vulnerabilities (RedHat)
- RHSA-2004:119-04 Updated OpenSSL packages fix vulnerabilities (Red Hat)
- RHSA-2004:139-05 - Stronghold 4: New release fixes OpenSSL and Apache issues (RedHat)
- Security Advisory: OpenSSL ASN.1 Vulnerability (Blue Coat Systems)