PT-2007-7474 · Openssl+1 · Openssl+1

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2007-5135

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.7 up to 0.9.7l OpenSSL versions 0.9.8 up to 0.9.8f
Description The issue is related to an off-by-one error in the SSL get shared ciphers function, which might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. This error was introduced as a result of a fix for a previous issue. As of the given date, it is unknown whether code execution is possible. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For OpenSSL versions 0.9.7 up to 0.9.7l, update to a version later than 0.9.7l to resolve the issue. For OpenSSL versions 0.9.8 up to 0.9.8f, update to a version later than 0.9.8f to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01464
BDU:2015-01466
BDU:2015-09567
CVE-2007-5135
DSA-1379-1
HPSBUX02292
OPENSUSE-SU-2024:11125-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2007:0813
RHSA-2007:0964
RHSA-2007:1003
RHSA-2007_0964
RHSA-2007_1003
SUSE-FU-2022:0445-1

Produtos afetados

Openssl
Red Hat