PT-2010-1087 · Openssl+1 · Openssl+1

Publicado

2010-03-26

·

Atualizado

2024-06-15

·

CVE-2010-0740

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8f through 0.9.8m
Description The issue allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number. This can be exploited to disrupt the confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For OpenSSL versions 0.9.8f through 0.9.8m, consider updating to a version newer than 0.9.8m to resolve the issue. As a temporary workaround, consider restricting access to TLS connections to minimize the risk of exploitation. Avoid using the ssl3 get record function in the affected OpenSSL versions until a patch is available.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09418
CVE-2010-0740
HPSBUX02517
HPSBUX02531
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
SUSE-FU-2022:0445-1

Produtos afetados

Hp-Ux
Openssl