PT-2004-1028 · Openssl+1 · Openssl+1

Published

2004-03-17

·

Updated

2025-01-16

·

CVE-2004-0079

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.6c through 0.9.6k OpenSSL versions 0.9.7a through 0.9.7c
Description The issue is related to a flaw in the do change cipher spec function that allows remote attackers to cause a denial of service via a crafted SSL/TLS handshake, triggering a null dereference. This may lead to a crash of applications that depend on OpenSSL, resulting in loss of availability. The exploitation of this issue can be done remotely.
Recommendations For OpenSSL versions 0.9.6c through 0.9.6k, update to a version outside of this range to resolve the issue. For OpenSSL versions 0.9.7a through 0.9.7c, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the do change cipher spec function until a patch is available.

Fix

DoS

Double Free

NULL Pointer Dereference

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2015-03282
BDU:2015-07476
BDU:2015-07478
BDU:2015-07479
BDU:2015-07484
BDU:2015-08201
BDU:2015-08203
BDU:2015-08204
BDU:2015-08208
CVE-2004-0079
DSA-465
RHSA-2004:120
RHSA-2005_830

Affected Products

Openssl
Red Hat