[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0079Date: (C)2004-11-23   (M)2024-02-22


The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score : 5.0
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: PARTIAL
Integrity: NONE 
Availability: HIGH 
  
Reference:
SECUNIA-11139
SECUNIA-17381
SECUNIA-17398
SECUNIA-17401
SECUNIA-18247
2004-0012
http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
http://marc.info/?l=bugtraq&m=107953412903636&w=2
SUNALERT-57524
BID-9899
APPLE-SA-2005-08-15
APPLE-SA-2005-08-17
CLA-2004:834
DSA-465
ESA-20040317-003
FEDORA-2004-095
FEDORA-2005-1042
FreeBSD-SA-04:05
GLSA-200403-03
MDKSA-2004:023
NetBSD-SA2004-005
O-101
RHSA-2004:120
RHSA-2004:121
RHSA-2004:139
RHSA-2005:829
RHSA-2005:830
SCOSA-2004.10
SSA:2004-077
SSRT4717
SuSE-SA:2004:007
TA04-078A
VU#288574
http://docs.info.apple.com/article.html?artnum=61798
http://lists.apple.com/mhonarc/security-announce/msg00045.html
http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm
http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US
http://www.openssl.org/news/secadv_20040317.txt
http://www.uniras.gov.uk/vuls/2004/224012/index.htm
openssl-dochangecipherspec-dos(15505)
oval:org.mitre.oval:def:2621
oval:org.mitre.oval:def:5770
oval:org.mitre.oval:def:870
oval:org.mitre.oval:def:975
oval:org.mitre.oval:def:9779

CWE    1
CWE-476
OVAL    1
oval:org.secpod.oval:def:1506549

© SecPod Technologies