VDB

CVE-2003-0544

CVE-2003-0544 PUBLISHED

Reported by mitre · Published October 1, 2003

OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a, *

Timeline

  • Sep 30, 2003 CVE Published
  • Feb 4, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Oct 16, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›