Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade openssl-develUpgrade opensslUpgrade openssl-perl | Dec 1, 2016 | Jan 14, 2010 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jan 14, 2010 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Jan 14, 2010 |
| Hpux | — | Update openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-MIS to the latest version | Aug 11, 2017 | Jan 14, 2010 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Sep 16, 2010 | Jan 14, 2010 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-devel | May 13, 2016 | Jan 14, 2010 |
| Suse | — | Upgrade openssl-x86Upgrade openssl-certsUpgrade libopenssl-develUpgrade openssl-devel-32bitUpgrade libopenssl0_9_8-32bitUpgrade sap-aio-releaseUpgrade opensslUpgrade openssl-64bitUpgrade openssl-develUpgrade libopenssl0_9_8Upgrade openssl-devel-64bitUpgrade openssl-docUpgrade openssl-32bitUpgrade libopenssl0_9_8-x86Upgrade libopenssl0_9_8-64bit | Feb 17, 2015 | Jan 14, 2010 |
| Ubuntu | — | Upgrade libssl0.9.8 | Nov 8, 2024 | Jan 14, 2010 |
| Vmsa 2010 0009 1 Service Console Package Openssl | — | Upgrade VMware ESX 4.0 to build number 256968 | Sep 2, 2010 | Jan 14, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub