5
CVSSv2

CVE-2004-0081

Published: 23/11/2004 Updated: 08/11/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OpenSSL 0.9.6 prior to 0.9.6d does not properly handle unknown message types, which allows remote malicious users to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firewall services module 1.1.3

cisco firewall services module 1.1_\\(3.005\\)

cisco firewall services module

cisco firewall services module 1.1.2

symantec clientless vpn gateway 4400 5.0

hp apache-based web server 2.0.43.00

hp apache-based web server 2.0.43.04

cisco firewall services module 2.1_\\(0.208\\)

hp aaa server

cisco ciscoworks common management foundation 2.1

cisco ciscoworks common services 2.2

avaya sg208 4.4

avaya sg5 4.2

avaya sg5 4.3

freebsd freebsd 5.1

hp hp-ux 8.05

openbsd openbsd 3.3

redhat linux 8.0

sco openserver 5.0.6

avaya sg203 4.4

avaya sg208

freebsd freebsd 4.8

freebsd freebsd 4.9

hp hp-ux 11.11

hp hp-ux 11.23

redhat enterprise linux desktop 3.0

redhat linux 7.2

redhat linux 7.3

avaya sg200 4.4

avaya sg203 4.31.29

apple mac os x server 10.3.3

freebsd freebsd 5.2.1

hp hp-ux 11.00

redhat enterprise linux 3.0

avaya converged communications server 2.0

avaya sg200 4.31.29

avaya sg5 4.4

apple mac os x 10.3.3

freebsd freebsd 5.2

openbsd openbsd 3.4

sco openserver 5.0.7

cisco ios 12.1\\(11b\\)e14

cisco ios 12.1\\(13\\)e9

cisco ios 12.1\\(11b\\)e

cisco ios 12.1\\(11b\\)e12

cisco ios 12.2za

cisco ios 12.1\\(11\\)e

cisco ios 12.2\\(14\\)sy1

cisco ios 12.2sy

cisco ios 12.1\\(19\\)e1

cisco ios 12.2\\(14\\)sy

4d webstar 4.0

4d webstar 5.2

avaya intuity_audix 5.1.46

avaya intuity_audix s3210

avaya vsu 5000_r2.0.1

avaya vsu 5x

checkpoint provider-1 4.1

cisco access_registrar

cisco application_and_content_networking_software

cisco webns 6.10

cisco webns 6.10_b4

hp wbem a.02.00.00

hp wbem a.02.00.01

lite speed_technologies_litespeed_web_server 1.2_rc1

lite speed_technologies_litespeed_web_server 1.2_rc2

neoteris instant_virtual_extranet 3.1

neoteris instant_virtual_extranet 3.2

novell edirectory 8.6.2

novell edirectory 8.7

novell edirectory 8.7.1

4d webstar 5.3

4d webstar 5.3.1

avaya intuity_audix

avaya vsu 5

avaya vsu 500

checkpoint firewall-1 next_generation_fp1

checkpoint firewall-1 next_generation_fp2

checkpoint vpn-1 next_generation_fp1

checkpoint vpn-1 vsx_ng_with_application_intelligence

cisco pix_firewall 6.2.2_.111

cisco threat_response

cisco webns 7.2_0.0.03

hp wbem a.01.05.08

lite speed_technologies_litespeed_web_server 1.2.1

lite speed_technologies_litespeed_web_server 1.2.2

lite speed_technologies_litespeed_web_server 1.3_rc3

neoteris instant_virtual_extranet 3.0

novell edirectory 8.5.12a

novell edirectory 8.5.27

openssl openssl 0.9.6d

openssl openssl 0.9.6e

openssl openssl 0.9.7

redhat openssl 0.9.6b-3

redhat openssl 0.9.7a-2

sgi propack 3.0

stonesoft servercluster 2.5

stonesoft stonebeat_securitycluster 2.0

stonesoft stonebeat_securitycluster 2.5

stonesoft stonegate 1.7

stonesoft stonegate 1.7.1

stonesoft stonegate 1.7.2

stonesoft stonegate 2.0.9

stonesoft stonegate 2.1

stonesoft stonegate_vpn_client 2.0.7

stonesoft stonegate_vpn_client 2.0.8

vmware gsx_server 2.5.1_build_5336

vmware gsx_server 3.0_build_7592

bluecoat proxysg

cisco call_manager

securecomputing sidewinder 5.2.0.01

securecomputing sidewinder 5.2.0.02

cisco pix_firewall_software 6.0

cisco pix_firewall_software 6.0\\(1\\)

cisco pix_firewall_software 6.1\\(2\\)

cisco pix_firewall_software 6.1\\(3\\)

cisco pix_firewall_software 6.2\\(3.100\\)

cisco pix_firewall_software 6.3

4d webstar 5.2.3

4d webstar 5.2.4

avaya vsu 10000_r2.0.1

avaya vsu 2000_r2.0.1

checkpoint firewall-1 2.0

checkpoint firewall-1 next_generation_fp0

checkpoint vpn-1 next_generation

checkpoint vpn-1 next_generation_fp0

cisco css11000_content_services_switch

cisco okena_stormwatch 3.2

cisco webns 7.10

cisco webns 7.10_.0.06s

lite speed_technologies_litespeed_web_server 1.1

lite speed_technologies_litespeed_web_server 1.1.1

lite speed_technologies_litespeed_web_server 1.3_rc1

openssl openssl 0.9.6f

openssl openssl 0.9.6g

dell bsafe_ssl-j 3.0

stonesoft servercluster 2.5.2

stonesoft stonebeat_fullcluster 1_2.0

stonesoft stonebeat_webcluster 2.0

stonesoft stonebeat_webcluster 2.5

stonesoft stonegate 2.0.1

stonesoft stonegate 2.0.4

stonesoft stonegate 2.2

stonesoft stonegate 2.2.1

stonesoft stonegate_vpn_client 2.0.9

tarantella tarantella_enterprise 3.20

avaya s8300 r2.0.0

avaya s8300 r2.0.1

cisco content_services_switch_11500

cisco gss_4480_global_site_selector

securecomputing sidewinder 5.2.0.03

securecomputing sidewinder 5.2.0.04

cisco pix_firewall_software 6.0\\(2\\)

cisco pix_firewall_software 6.0\\(3\\)

cisco pix_firewall_software 6.1\\(4\\)

cisco pix_firewall_software 6.1\\(5\\)

cisco pix_firewall_software 6.3\\(1\\)

cisco pix_firewall_software 6.3\\(2\\)

cisco pix_firewall_software 6.3\\(3.102\\)

lite speed_technologies_litespeed_web_server 1.3_rc2

novell edirectory 8.0

novell edirectory 8.5

novell imanager 2.0

openssl openssl 0.9.6c

openssl openssl 0.9.6j

openssl openssl 0.9.6k

openssl openssl 0.9.7c

redhat openssl 0.9.6-15

sgi propack 2.3

sgi propack 2.4

stonesoft stonebeat_fullcluster 2.5

stonesoft stonebeat_fullcluster 3.0

stonesoft stonegate 1.6.2

stonesoft stonegate 1.6.3

stonesoft stonegate 2.0.7

stonesoft stonegate 2.0.8

stonesoft stonegate_vpn_client 1.7.2

stonesoft stonegate_vpn_client 2.0

vmware gsx_server 2.0

vmware gsx_server 2.0.1_build_2129

vmware gsx_server 2.5.1

avaya s8700 r2.0.0

avaya s8700 r2.0.1

cisco secure_content_accelerator 10000

securecomputing sidewinder 5.2

bluecoat cacheos_ca_sa 4.1.10

bluecoat cacheos_ca_sa 4.1.12

cisco pix_firewall_software 6.1

cisco pix_firewall_software 6.1\\(1\\)

cisco pix_firewall_software 6.2\\(2\\)

cisco pix_firewall_software 6.2\\(3\\)

4d webstar 5.2.1

4d webstar 5.2.2

avaya intuity_audix s3400

avaya vsu 100_r2.0.1

avaya vsu 7500_r2.0.1

checkpoint firewall-1

cisco css_secure_content_accelerator 1.0

cisco css_secure_content_accelerator 2.0

cisco webns 7.1_0.1.02

cisco webns 7.1_0.2.06

lite speed_technologies_litespeed_web_server 1.0.1

lite speed_technologies_litespeed_web_server 1.0.2

lite speed_technologies_litespeed_web_server 1.0.3

lite speed_technologies_litespeed_web_server 1.3

lite speed_technologies_litespeed_web_server 1.3.1

neoteris instant_virtual_extranet 3.3

neoteris instant_virtual_extranet 3.3.1

novell imanager 1.5

openssl openssl 0.9.6h

openssl openssl 0.9.6i

openssl openssl 0.9.7a

openssl openssl 0.9.7b

dell bsafe_ssl-j 3.0.1

dell bsafe_ssl-j 3.1

stonesoft stonebeat_fullcluster 1_3.0

stonesoft stonebeat_fullcluster 2.0

stonesoft stonegate 1.5.17

stonesoft stonegate 1.5.18

stonesoft stonegate 2.0.5

stonesoft stonegate 2.0.6

stonesoft stonegate 2.2.4

stonesoft stonegate_vpn_client 1.7

tarantella tarantella_enterprise 3.30

tarantella tarantella_enterprise 3.40

avaya s8500 r2.0.0

avaya s8500 r2.0.1

cisco gss_4490_global_site_selector

cisco mds_9000

securecomputing sidewinder 5.2.1

securecomputing sidewinder 5.2.1.02

sun crypto_accelerator_4000 1.0

cisco pix_firewall_software 6.0\\(4\\)

cisco pix_firewall_software 6.0\\(4.101\\)

cisco pix_firewall_software 6.2

cisco pix_firewall_software 6.2\\(1\\)

cisco pix_firewall_software 6.3\\(3.109\\)

Vendor Advisories

Synopsis openssl security update Type/Severity Security Advisory: Important Topic Updated OpenSSL packages that fix several remote denial of servicevulnerabilities are available for Red Hat Enterprise Linux 3 Description The OpenSSL toolkit implements Secure Sockets Layer (SSL v2/v3),Trans ...
Two vulnerabilities were discovered in openssl, an implementation of the SSL protocol, using the Codenomicon TLS Test Tool More information can be found in the following NISCC Vulnerability Advisory and this OpenSSL advisory The Common Vulnerabilities and Exposures project identified the following vulnerabilities: CAN-2004-0079 Null-pointer a ...
A new vulnerability in the OpenSSL implementation for SSL has been announced on March 17, 2004 An affected network device running an SSL server based on an affected OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack There are workarounds available to mitigate the effects of this vulnerability on Cisco produ ...

References

NVD-CWE-Otherhttp://www.kb.cert.org/vuls/id/465542http://www.securityfocus.com/bid/9899http://www.uniras.gov.uk/vuls/2004/224012/index.htmhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834http://www.linuxsecurity.com/advisories/engarde_advisory-4135.htmlhttp://www.debian.org/security/2004/dsa-465http://rhn.redhat.com/errata/RHSA-2004-119.htmlhttp://www.redhat.com/support/errata/RHSA-2004-121.htmlftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txtftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.aschttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524http://www.us-cert.gov/cas/techalerts/TA04-078A.htmlhttp://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtmlhttp://fedoranews.org/updates/FEDORA-2004-095.shtmlhttp://security.gentoo.org/glsa/glsa-200403-03.xmlhttp://www.redhat.com/support/errata/RHSA-2004-120.htmlhttp://www.redhat.com/support/errata/RHSA-2004-139.htmlhttp://www.trustix.org/errata/2004/0012http://secunia.com/advisories/11139http://marc.info/?l=bugtraq&m=107955049331965&w=2http://marc.info/?l=bugtraq&m=108403850228012&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/15509https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A902https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A871https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11755https://access.redhat.com/errata/RHSA-2004:120https://nvd.nist.govhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040317-opensslhttps://www.kb.cert.org/vuls/id/465542