Oval Definition:oval:org.mitre.oval:def:9754
Revision Date:2013-04-29Version:12
Title:Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Description:Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2008-1678
Platform(s):CentOS Linux 5
Oracle Linux 5
Red Hat Enterprise Linux 5
Product(s):
Definition Synopsis
  • RHEL5, CentOS5 or Oracle Linux 5
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • OR Oracle Linux 5.x
  • AND Configuration section
  • httpd-manual is earlier than 0:2.2.3-22.el5_3.1
  • OR httpd-devel is earlier than 0:2.2.3-22.el5_3.1
  • OR mod_ssl is earlier than 0:2.2.3-22.el5_3.1
  • OR httpd is earlier than 0:2.2.3-22.el5_3.1
  • BACK