imPC@ndo EN

Tracker / CVE-2004-0112

CVE-2004-0112

Media 5.0

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

Prodotti e versioni affette

4d webstar
apple mac_os_x
apple mac_os_x_server
avaya converged_communications_server
avaya intuity_audix
avaya s8300
avaya s8500
avaya s8700
avaya sg200
avaya sg203
avaya sg208
avaya sg5
avaya vsu
bluecoat cacheos_ca_sa
bluecoat proxysg
checkpoint firewall-1
checkpoint provider-1
checkpoint vpn-1
cisco access_registrar
cisco application_and_content_networking_software
cisco call_manager
cisco ciscoworks_common_management_foundation
cisco ciscoworks_common_services
cisco content_services_switch_11500
cisco css11000_content_services_switch
cisco css_secure_content_accelerator
cisco firewall_services_module
cisco gss_4480_global_site_selector
cisco gss_4490_global_site_selector
cisco ios
cisco mds_9000
cisco okena_stormwatch
cisco pix_firewall
cisco pix_firewall_software
cisco secure_content_accelerator
cisco threat_response
cisco webns
dell bsafe_ssl-j
forcepoint stonegate
freebsd freebsd
hp aaa_server
hp apache-based_web_server
hp hp-ux
hp wbem
litespeedtech litespeed_web_server
neoteris instant_virtual_extranet
novell edirectory
novell imanager
openbsd openbsd
openssl openssl
redhat enterprise_linux
redhat enterprise_linux_desktop
redhat linux
redhat openssl
sco openserver
securecomputing sidewinder
sgi propack
stonesoft servercluster
stonesoft stonebeat_fullcluster
stonesoft stonebeat_securitycluster

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti