Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssl | — | Apply OS X security update 2008-005 | Dec 16, 2011 | Sep 27, 2007 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Sep 27, 2007 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 27, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/openssl.Upgrade app-emulation/emul-linux-x86-baselibs. | Oct 30, 2017 | Sep 27, 2007 |
| Oracle_linux | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-devel | May 13, 2016 | Sep 27, 2007 |
| Suse | — | Upgrade compat-openssl097g-32bitUpgrade openssl-develUpgrade openssl-devel-32bitUpgrade suse-releaseUpgrade openssl-certsUpgrade openssl-x86Upgrade compat-openssl097gUpgrade libopenssl0_9_8-32bitUpgrade opensslUpgrade openssl-32bitUpgrade libopenssl0_9_8-64bitUpgrade libopenssl0_9_8Upgrade compat-openssl097g-64bitUpgrade libopenssl-develUpgrade openssl-docUpgrade openssl-devel-64bitUpgrade openssl-64bit | Feb 17, 2015 | Sep 27, 2007 |
| Ubuntu | — | Upgrade libssl0.9.8 | Nov 8, 2024 | Sep 27, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub