PT-2011-1149 · Openssl+2 · Openssl+2

Neel Mehta

·

Publicado

2011-02-08

·

Atualizado

2024-06-15

·

CVE-2011-0014

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8h through 0.9.8q OpenSSL versions 1.0.0 through 1.0.0c OpenSSL versions prior to 1.0.0e
Description The issue allows remote attackers to cause a denial of service (crash) and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access. Exploitation of the vulnerabilities may lead to a violation of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For OpenSSL versions 0.9.8h through 0.9.8q, update to a version later than 0.9.8q. For OpenSSL versions 1.0.0 through 1.0.0c, update to a version later than 1.0.0c. For OpenSSL versions prior to 1.0.0e, update to version 1.0.0e or later.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09418
CVE-2011-0014
DSA-2162-1
HPSBUX02689
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2011:0677
RHSA-2011_0677
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Produtos afetados

Hp-Ux
Openssl
Red Hat