Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800809
Kategorie:Denial of Service
Titel:Denial Of Service Vulnerability in OpenSSL (Jun 2009) - Linux
Zusammenfassung:OpenSSL is prone to a Denial of Service (DoS) vulnerability.
Beschreibung:Summary:
OpenSSL is prone to a Denial of Service (DoS) vulnerability.

Vulnerability Insight:
A NULL pointer dereference error in ssl/s3_pkt.c file which does not properly
check the input packets value via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

Vulnerability Impact:
Successful exploitation will allow attacker to cause DTLS server crash.

Affected Software/OS:
OpenSSL version prior to 0.9.8i.

Solution:
Upgrade to OpenSSL version 0.9.8i or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-1386
35174
http://www.securityfocus.com/bid/35174
35571
http://secunia.com/advisories/35571
35685
http://secunia.com/advisories/35685
35729
http://secunia.com/advisories/35729
36533
http://secunia.com/advisories/36533
38794
http://secunia.com/advisories/38794
38834
http://secunia.com/advisories/38834
8873
https://www.exploit-db.com/exploits/8873
ADV-2010-0528
http://www.vupen.com/english/advisories/2010/0528
HPSBMA02492
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444
NetBSD-SA2009-009
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc
RHSA-2009:1335
http://www.redhat.com/support/errata/RHSA-2009-1335.html
SSRT100079
SUSE-SR:2009:012
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
USN-792-1
http://www.ubuntu.com/usn/USN-792-1
[oss-security] 20090602 Re: Two OpenSSL DTLS remote DoS
http://www.openwall.com/lists/oss-security/2009/06/02/1
[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates
http://lists.vmware.com/pipermail/security-announce/2010/000082.html
http://cvs.openssl.org/chngview?cn=17369
http://rt.openssl.org/Ticket/Display.html?id=1679&user=guest&pass=guest
openssl-changecipherspec-dos(50963)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50963
oval:org.mitre.oval:def:11179
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11179
oval:org.mitre.oval:def:7469
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7469
CopyrightCopyright (C) 2009 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.