Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2003-0545

Опубликовано: 30 сент. 2003
Источник: redhat
EPSS Высокий

Описание

Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.

Отчет

Not vulnerable. The OpenSSL packages in Red Hat Enterprise Linux 2.1 were not affected by this issue. The OpenSSL packages in Red Hat Enterprise Linux 3 and 4 contain a backported patch since their initial release (openssl), or were not affected by this issue (openssl096b). The OpenSSL packages in Red Hat Enterprise Linux 5 are based on fixed upstream release (openssl), or contain backported patch since their initial release (openssl097a).

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=104893CAN-2003-0543/0544 OpenSSL ASN.1 protocol crashes

EPSS

Процентиль: 99%
0.74574
Высокий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 21 года назад

Описание отсутствует

CVSS3: 9.8
nvd
больше 21 года назад

Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.

CVSS3: 9.8
debian
больше 21 года назад

Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to ...

CVSS3: 9.8
github
около 3 лет назад

Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.

fstec
больше 21 года назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 99%
0.74574
Высокий