Описание
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 3 | openssl | Will not fix | ||
Red Hat Enterprise Linux 4 | openssl096b | Will not fix | ||
Red Hat Enterprise Linux 5 | openssl097a | Will not fix | ||
Red Hat Enterprise Linux 6 | openssl098e | Will not fix | ||
Red Hat Enterprise Linux 4 | openssl | Fixed | RHSA-2012:0086 | 01.02.2012 |
Red Hat Enterprise Linux 5 | openssl | Fixed | RHSA-2012:0060 | 24.01.2012 |
Red Hat Enterprise Linux 6 | openssl | Fixed | RHSA-2012:0059 | 24.01.2012 |
Red Hat JBoss Enterprise Application Platform 5.1 | Fixed | RHSA-2012:1307 | 24.09.2012 | |
Red Hat JBoss Enterprise Application Platform 6.0 | Fixed | RHSA-2012:1308 | 24.09.2012 | |
Red Hat JBoss Web Server 1.0 | Fixed | RHSA-2012:1306 | 24.09.2012 |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS2
Связанные уязвимости
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0 ...
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
4.3 Medium
CVSS2