Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssl | — | Apply OS X security update 2008-005 | Dec 16, 2011 | Sep 27, 2007 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Sep 27, 2007 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 27, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/openssl.Upgrade app-emulation/emul-linux-x86-baselibs. | Oct 30, 2017 | Sep 27, 2007 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-devel | May 13, 2016 | Sep 27, 2007 |
| Suse | — | Upgrade libopenssl0_9_8-hmacUpgrade libopenssl1_0_0Upgrade libopenssl-develUpgrade libopenssl1_0_0-32bitUpgrade openssl1-docUpgrade libopenssl0_9_8-hmac-32bitUpgrade openssl-docUpgrade opensslUpgrade libopenssl0_9_8-32bitUpgrade libopenssl0_9_8Upgrade libopenssl0_9_8-x86Upgrade openssl1Upgrade libopenssl-fips-providerUpgrade libopenssl1-devel | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libssl0.9.8 | Nov 8, 2024 | Sep 27, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub