Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssl | Jul 30, 2024 | May 29, 2008 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | May 29, 2008 |
| Oracle_linux | — | Upgrade openssl-develUpgrade openssl-staticUpgrade openssl-perlUpgrade openssl | May 13, 2016 | May 29, 2008 |
| Suse | — | Upgrade libopenssl0_9_8-x86Upgrade libopenssl1_0_0Upgrade openssl1Upgrade libopenssl1-develUpgrade openssl-docUpgrade opensslUpgrade libopenssl1_0_0-32bitUpgrade libopenssl0_9_8Upgrade libopenssl0_9_8-hmac-32bitUpgrade openssl1-docUpgrade libopenssl0_9_8-hmacUpgrade libopenssl-develUpgrade libopenssl0_9_8-32bit | Aug 9, 2024 | May 29, 2008 |
| Ubuntu | — | Upgrade libssl0.9.8 | Nov 8, 2024 | May 29, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub