Oval Definition:oval:org.mitre.oval:def:1049
Revision Date:2007-04-25Version:20
Title:Red Hat OpenSSL Kerberos Handshake Vulnerability
Description:The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2004-0112
Platform(s):Red Hat Linux 9
Product(s):OpenSSL
Definition Synopsis
  • Red Hat 9 is installed
  • AND ix86 architecture
  • AND openssl version is less than 0.9.7a-20
  • AND openssl-devel version is less than 0.9.7a-20
  • AND openssl-perl version is less than 0.9.7a-20
  • AND openssl096 version is less than 0.9.6-25.9
  • AND openssl096b version is less than 0.9.6b-15
  • BACK