Revision Date: | 2013-04-29 | Version: | 12 | Title: | Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible. | Description: | Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible. | Family: | unix | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2007-5135
| Platform(s): | CentOS Linux 3 CentOS Linux 4 CentOS Linux 5 Oracle Linux 4 Oracle Linux 5 Red Hat Enterprise Linux 3 Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5
| Product(s): | | Definition Synopsis | OS Section: RHEL3, CentOS3 RHEL3 or CentOS3
The operating system installed on the system is Red Hat Enterprise Linux 3
OR CentOS Linux 3.x
AND Configuration section
openssl-perl is earlier than 0:0.9.7a-33.24
OR openssl-devel is earlier than 0:0.9.7a-33.24
OR openssl is earlier than 0:0.9.7a-33.24
OR OS Section: RHEL4, CentOS4, Oracle Linux 4
RHEL4, CentOS4 or Oracle Linux 4
The operating system installed on the system is Red Hat Enterprise Linux 4
OR CentOS Linux 4.x
OR Oracle Linux 4.x
AND Configuration section
openssl-perl is earlier than 0:0.9.7a-43.17.el4_6.1
OR openssl-devel is earlier than 0:0.9.7a-43.17.el4_6.1
OR openssl is earlier than 0:0.9.7a-43.17.el4_6.1
OR OS Section: RHEL5, CentOS5, Oracle Linux 5
RHEL5, CentOS5 or Oracle Linux 5
The operating system installed on the system is Red Hat Enterprise Linux 5
OR The operating system installed on the system is CentOS Linux 5.x
OR Oracle Linux 5.x
AND Configuration section
openssl-perl is earlier than 0:0.9.8b-8.3.el5_0.2
OR openssl-devel is earlier than 0:0.9.8b-8.3.el5_0.2
OR openssl is earlier than 0:0.9.8b-8.3.el5_0.2
|
|