The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssl | — | Apply OS X security update 2005-007 | Dec 16, 2011 | Nov 23, 2004 |
| Cisco Asa | — | Upgrade to Cisco ASA version 6.2(3.107)Upgrade to Cisco ASA version 6.3(3.124)Upgrade to Cisco ASA version 6.1(5.102)Upgrade to Cisco ASA version 6.0(4.102) | Feb 9, 2017 | Nov 23, 2004 |
| Cisco Ios | — | Upgrade to the latest version of Cisco IOS to resolve this vulnerability | May 2, 2018 | Nov 23, 2004 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Nov 23, 2004 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Nov 23, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub