5
CVSSv2

CVE-2004-0081

Published: 23/11/2004 Updated: 08/11/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OpenSSL 0.9.6 prior to 0.9.6d does not properly handle unknown message types, which allows remote malicious users to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco firewall services module

symantec clientless vpn gateway 4400 5.0

hp apache-based web server 2.0.43.00

cisco firewall services module 1.1.3

cisco firewall services module 1.1.2

hp aaa server

cisco firewall services module 1.1 (3.005)

hp apache-based web server 2.0.43.04

cisco firewall services module 2.1 (0.208)

avaya sg203 4.4

hp hp-ux 11.11

redhat enterprise linux desktop 3.0

hp hp-ux 11.23

cisco ciscoworks common management foundation 2.1

freebsd freebsd 5.1

avaya sg208 4.4

redhat enterprise linux 3.0

avaya sg200 4.4

avaya sg5 4.4

redhat linux 7.2

cisco ciscoworks common services 2.2

openbsd openbsd 3.3

apple mac os x server 10.3.3

redhat linux 8.0

redhat linux 7.3

avaya converged communications server 2.0

sco openserver 5.0.7

hp hp-ux 11.00

avaya sg5 4.2

avaya sg208

freebsd freebsd 5.2

avaya sg200 4.31.29

freebsd freebsd 4.8

avaya sg203 4.31.29

hp hp-ux 8.05

apple mac os x 10.3.3

freebsd freebsd 5.2.1

sco openserver 5.0.6

avaya sg5 4.3

freebsd freebsd 4.9

openbsd openbsd 3.4

cisco ios 12.1(11)e

cisco ios 12.1(11b)e

cisco ios 12.1(11b)e12

cisco ios 12.1(11b)e14

cisco ios 12.1(13)e9

cisco ios 12.1(19)e1

cisco ios 12.2(14)sy

cisco ios 12.2(14)sy1

cisco ios 12.2sy

cisco ios 12.2za

4d webstar 4.0

4d webstar 5.2

4d webstar 5.2.1

4d webstar 5.2.2

4d webstar 5.2.3

4d webstar 5.2.4

4d webstar 5.3

4d webstar 5.3.1

avaya intuity audix

avaya intuity audix 5.1.46

avaya intuity audix s3210

avaya intuity audix s3400

avaya vsu 5

avaya vsu 5x

avaya vsu 100 r2.0.1

avaya vsu 500

avaya vsu 2000 r2.0.1

avaya vsu 5000 r2.0.1

avaya vsu 7500 r2.0.1

avaya vsu 10000 r2.0.1

checkpoint firewall-1

checkpoint firewall-1 2.0

checkpoint firewall-1 next generation fp0

checkpoint firewall-1 next generation fp1

checkpoint firewall-1 next generation fp2

checkpoint provider-1 4.1

checkpoint vpn-1 next generation

checkpoint vpn-1 next generation fp0

checkpoint vpn-1 next generation fp1

checkpoint vpn-1 vsx ng with application intelligence

cisco access registrar

cisco application and content networking software

cisco css secure content accelerator 1.0

cisco css secure content accelerator 2.0

cisco css11000 content services switch

cisco okena stormwatch 3.2

cisco pix firewall 6.2.2 .111

cisco threat response

cisco webns 6.10

cisco webns 6.10 b4

cisco webns 7.1 0.1.02

cisco webns 7.1 0.2.06

cisco webns 7.2 0.0.03

cisco webns 7.10

cisco webns 7.10 .0.06s

dell bsafe ssl-j 3.0

dell bsafe ssl-j 3.0.1

dell bsafe ssl-j 3.1

hp wbem a.01.05.08

hp wbem a.02.00.00

hp wbem a.02.00.01

lite speed technologies litespeed web server 1.0.1

lite speed technologies litespeed web server 1.0.2

lite speed technologies litespeed web server 1.0.3

lite speed technologies litespeed web server 1.1

lite speed technologies litespeed web server 1.1.1

lite speed technologies litespeed web server 1.2.1

lite speed technologies litespeed web server 1.2.2

lite speed technologies litespeed web server 1.2 rc1

lite speed technologies litespeed web server 1.2 rc2

lite speed technologies litespeed web server 1.3

lite speed technologies litespeed web server 1.3.1

lite speed technologies litespeed web server 1.3 rc1

lite speed technologies litespeed web server 1.3 rc2

lite speed technologies litespeed web server 1.3 rc3

neoteris instant virtual extranet 3.0

neoteris instant virtual extranet 3.1

neoteris instant virtual extranet 3.2

neoteris instant virtual extranet 3.3

neoteris instant virtual extranet 3.3.1

novell edirectory 8.0

novell edirectory 8.5

novell edirectory 8.5.12a

novell edirectory 8.5.27

novell edirectory 8.6.2

novell edirectory 8.7

novell edirectory 8.7.1

novell imanager 1.5

novell imanager 2.0

openssl openssl 0.9.6c

openssl openssl 0.9.6d

openssl openssl 0.9.6e

openssl openssl 0.9.6f

openssl openssl 0.9.6g

openssl openssl 0.9.6h

openssl openssl 0.9.6i

openssl openssl 0.9.6j

openssl openssl 0.9.6k

openssl openssl 0.9.7

openssl openssl 0.9.7a

openssl openssl 0.9.7b

openssl openssl 0.9.7c

redhat openssl 0.9.6-15

redhat openssl 0.9.6b-3

redhat openssl 0.9.7a-2

sgi propack 2.3

sgi propack 2.4

sgi propack 3.0

stonesoft servercluster 2.5

stonesoft servercluster 2.5.2

stonesoft stonebeat fullcluster 1 2.0

stonesoft stonebeat fullcluster 1 3.0

stonesoft stonebeat fullcluster 2.0

stonesoft stonebeat fullcluster 2.5

stonesoft stonebeat fullcluster 3.0

stonesoft stonebeat securitycluster 2.0

stonesoft stonebeat securitycluster 2.5

stonesoft stonebeat webcluster 2.0

stonesoft stonebeat webcluster 2.5

stonesoft stonegate 1.5.17

stonesoft stonegate 1.5.18

stonesoft stonegate 1.6.2

stonesoft stonegate 1.6.3

stonesoft stonegate 1.7

stonesoft stonegate 1.7.1

stonesoft stonegate 1.7.2

stonesoft stonegate 2.0.1

stonesoft stonegate 2.0.4

stonesoft stonegate 2.0.5

stonesoft stonegate 2.0.6

stonesoft stonegate 2.0.7

stonesoft stonegate 2.0.8

stonesoft stonegate 2.0.9

stonesoft stonegate 2.1

stonesoft stonegate 2.2

stonesoft stonegate 2.2.1

stonesoft stonegate 2.2.4

stonesoft stonegate vpn client 1.7

stonesoft stonegate vpn client 1.7.2

stonesoft stonegate vpn client 2.0

stonesoft stonegate vpn client 2.0.7

stonesoft stonegate vpn client 2.0.8

stonesoft stonegate vpn client 2.0.9

tarantella tarantella enterprise 3.20

tarantella tarantella enterprise 3.30

tarantella tarantella enterprise 3.40

vmware gsx server 2.0

vmware gsx server 2.0.1 build 2129

vmware gsx server 2.5.1

vmware gsx server 2.5.1 build 5336

vmware gsx server 3.0 build 7592

avaya s8300 r2.0.0

avaya s8300 r2.0.1

avaya s8500 r2.0.0

avaya s8500 r2.0.1

avaya s8700 r2.0.0

avaya s8700 r2.0.1

bluecoat proxysg

cisco call manager

cisco content services switch 11500

cisco gss 4480 global site selector

cisco gss 4490 global site selector

cisco mds 9000

cisco secure content accelerator 10000

securecomputing sidewinder 5.2

securecomputing sidewinder 5.2.0.01

securecomputing sidewinder 5.2.0.02

securecomputing sidewinder 5.2.0.03

securecomputing sidewinder 5.2.0.04

securecomputing sidewinder 5.2.1

securecomputing sidewinder 5.2.1.02

sun crypto accelerator 4000 1.0

bluecoat cacheos ca sa 4.1.10

bluecoat cacheos ca sa 4.1.12

cisco pix firewall software 6.0

cisco pix firewall software 6.0(1)

cisco pix firewall software 6.0(2)

cisco pix firewall software 6.0(3)

cisco pix firewall software 6.0(4)

cisco pix firewall software 6.0(4.101)

cisco pix firewall software 6.1

cisco pix firewall software 6.1(1)

cisco pix firewall software 6.1(2)

cisco pix firewall software 6.1(3)

cisco pix firewall software 6.1(4)

cisco pix firewall software 6.1(5)

cisco pix firewall software 6.2

cisco pix firewall software 6.2(1)

cisco pix firewall software 6.2(2)

cisco pix firewall software 6.2(3)

cisco pix firewall software 6.2(3.100)

cisco pix firewall software 6.3

cisco pix firewall software 6.3(1)

cisco pix firewall software 6.3(2)

cisco pix firewall software 6.3(3.102)

cisco pix firewall software 6.3(3.109)

Vendor Advisories

Synopsis openssl security update Type/Severity Security Advisory: Important Topic Updated OpenSSL packages that fix several remote denial of servicevulnerabilities are available for Red Hat Enterprise Linux 3 Description The OpenSSL toolkit implements Secure Sockets Layer (SSL v2/v3),Trans ...
Two vulnerabilities were discovered in openssl, an implementation of the SSL protocol, using the Codenomicon TLS Test Tool More information can be found in the following NISCC Vulnerability Advisory and this OpenSSL advisory The Common Vulnerabilities and Exposures project identified the following vulnerabilities: CAN-2004-0079 Null-pointer a ...
A new vulnerability in the OpenSSL implementation for SSL has been announced on March 17, 2004 An affected network device running an SSL server based on an affected OpenSSL implementation may be vulnerable to a Denial of Service (DoS) attack There are workarounds available to mitigate the effects of this vulnerability on Cisco produ ...

References

NVD-CWE-Otherhttp://www.kb.cert.org/vuls/id/465542http://www.securityfocus.com/bid/9899http://www.uniras.gov.uk/vuls/2004/224012/index.htmhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834http://www.linuxsecurity.com/advisories/engarde_advisory-4135.htmlhttp://www.debian.org/security/2004/dsa-465http://rhn.redhat.com/errata/RHSA-2004-119.htmlhttp://www.redhat.com/support/errata/RHSA-2004-121.htmlftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txtftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.aschttp://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524http://www.us-cert.gov/cas/techalerts/TA04-078A.htmlhttp://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtmlhttp://fedoranews.org/updates/FEDORA-2004-095.shtmlhttp://security.gentoo.org/glsa/glsa-200403-03.xmlhttp://www.redhat.com/support/errata/RHSA-2004-120.htmlhttp://www.redhat.com/support/errata/RHSA-2004-139.htmlhttp://www.trustix.org/errata/2004/0012http://secunia.com/advisories/11139http://marc.info/?l=bugtraq&m=107955049331965&w=2http://marc.info/?l=bugtraq&m=108403850228012&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/15509https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A902https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A871https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11755https://access.redhat.com/errata/RHSA-2004:120https://nvd.nist.govhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040317-opensslhttps://www.kb.cert.org/vuls/id/465542