PT-2013-1056 · Openssl+4 · Openssl+4

David Carlin

·

Published

2013-12-14

·

Updated

2024-06-15

·

CVE-2013-6449

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.1j OpenSSL versions 1.0.1
Description The issue concerns multiple vulnerabilities in the OpenSSL package that can be exploited remotely, potentially leading to breaches in confidentiality, integrity, and availability of protected information. A specific flaw in the ssl get algorithm2 function can cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For OpenSSL versions prior to 1.0.1j, update to version 1.0.1j or later to resolve the issue. For OpenSSL version 1.0.1, consider disabling the ssl get algorithm2 function as a temporary workaround until a patch is available. Restrict access to TLS 1.2 clients to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1019
BDU:2015-01314
BDU:2015-09775
CESA-2014_0015
CVE-2013-6449
DSA-2833-1
MGASA-2014-0008
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2014:0015
RHSA-2014:0041
RHSA-2014_0015
SUSE-FU-2022:0445-1

Affected Products

Alt Linux
Centos
Ibm Aix
Openssl
Red Hat