Описание
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | released  | 0.9.8a-7ubuntu0.4 | 
| devel | released  | 0.9.8e-5ubuntu2 | 
| edgy | released  | 0.9.8b-2ubuntu2.1 | 
| feisty | released  | 0.9.8c-4ubuntu0.1 | 
| gutsy | released  | 0.9.8e-5ubuntu2 | 
| hardy | released  | 0.9.8e-5ubuntu2 | 
| intrepid | released  | 0.9.8e-5ubuntu2 | 
| jaunty | released  | 0.9.8e-5ubuntu2 | 
| karmic | released  | 0.9.8e-5ubuntu2 | 
| upstream | released  | 0.9.8f | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | ignored  | end of life | 
| devel | DNE  | |
| edgy | ignored  | end of life, was needed | 
| feisty | ignored  | end of life, was needed | 
| gutsy | DNE  | |
| hardy | DNE  | |
| intrepid | DNE  | |
| jaunty | DNE  | |
| karmic | DNE  | |
| upstream | needs-triage  | 
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9 ...
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
6.8 Medium
CVSS2