PT-2007-7474 · Openssl+1 · Openssl+1
Publicado
1970-01-01
·
Atualizado
2024-06-15
·
CVE-2007-5135
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 0.9.7 up to 0.9.7l
OpenSSL versions 0.9.8 up to 0.9.8f
Description
The issue is related to an off-by-one error in the SSL get shared ciphers function, which might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. This error was introduced as a result of a fix for a previous issue. As of the given date, it is unknown whether code execution is possible. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations
For OpenSSL versions 0.9.7 up to 0.9.7l, update to a version later than 0.9.7l to resolve the issue.
For OpenSSL versions 0.9.8 up to 0.9.8f, update to a version later than 0.9.8f to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openssl
Red Hat