PT-2008-1123 · Openssl · Openssl
Published
2008-05-29
·
Updated
2024-06-15
·
CVE-2008-1672
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 0.9.8f through 0.9.8g
Description
The issue allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses particular cipher suites, which triggers a NULL pointer dereference. This can lead to disruption of protected information availability.
Recommendations
For versions 0.9.8f and 0.9.8g, update to a version newer than 0.9.8g to resolve the issue. As a temporary workaround, consider restricting the use of particular cipher suites in TLS handshakes to minimize the risk of exploitation.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl