PT-2007-1117 · Openssl+3 · Openssl+3

Published

2007-10-12

·

Updated

2018-10-15

·

CVE-2007-4995

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenSSL versions prior to 0.9.8f Gentoo Linux (affected versions not specified) 1C:Предприятие (affected versions not specified)
Description: The issue is related to an off-by-one error in the DTLS implementation of OpenSSL, which can be exploited remotely. This can lead to the execution of arbitrary code, disruption of confidentiality, integrity, and availability of protected information, and potentially allow an attacker to obtain access to encrypted data without knowledge of the encryption key.
Recommendations: For OpenSSL versions prior to 0.9.8f, update to version 0.9.8f or later. For Gentoo Linux, update the OpenSSL package to a version that includes the fix for this issue. For 1C:Предприятие, consider restricting access to the vulnerable components of the system until a patch is available, and update the OpenSSL package to a version that includes the fix for this issue. As a temporary workaround, consider disabling the use of DTLS in OpenSSL until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09605
BDU:2015-09905
CVE-2007-4995
DSA-1571-1
HPSBUX02296
RHSA-2007:0964
RHSA-2007_0964
SUSE-FU-2022:0445-1

Affected Products

1С:Предприятие
Gentoo Linux
Openssl
Red Hat