Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-5135

Опубликовано: 27 сент. 2007
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6.8

Описание

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.

РелизСтатусПримечание
dapper

released

0.9.8a-7ubuntu0.4
devel

released

0.9.8e-5ubuntu2
edgy

released

0.9.8b-2ubuntu2.1
feisty

released

0.9.8c-4ubuntu0.1
gutsy

released

0.9.8e-5ubuntu2
hardy

released

0.9.8e-5ubuntu2
intrepid

released

0.9.8e-5ubuntu2
jaunty

released

0.9.8e-5ubuntu2
karmic

released

0.9.8e-5ubuntu2
upstream

released

0.9.8f

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

ignored

end of life, was needed
feisty

ignored

end of life, was needed
gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 96%
0.30644
Средний

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.

nvd
больше 17 лет назад

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.

debian
больше 17 лет назад

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9 ...

github
около 3 лет назад

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.

fstec
больше 10 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 96%
0.30644
Средний

6.8 Medium

CVSS2

Уязвимость CVE-2007-5135