PT-2007-7474 · Openssl+1 · Openssl+1

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2007-5135

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.7 up to 0.9.7l OpenSSL versions 0.9.8 up to 0.9.8f
Description The issue is related to an off-by-one error in the SSL get shared ciphers function, which might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. This error was introduced as a result of a fix for a previous issue. As of the given date, it is unknown whether code execution is possible. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For OpenSSL versions 0.9.7 up to 0.9.7l, update to a version later than 0.9.7l to resolve the issue. For OpenSSL versions 0.9.8 up to 0.9.8f, update to a version later than 0.9.8f to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01464
BDU:2015-01466
BDU:2015-09567
CVE-2007-5135
DSA-1379-1
HPSBUX02292
OPENSUSE-SU-2024:11125-1
OPENSUSE-SU-2024:11126-1
OPENSUSE-SU-2024:11127-1
RHSA-2007:0813
RHSA-2007:0964
RHSA-2007:1003
RHSA-2007_0964
RHSA-2007_1003
SUSE-FU-2022:0445-1

Affected Products

Openssl
Red Hat