VDB

CVE-2003-0544

CVE-2003-0544 PUBLISHED

Reported by mitre · Published October 1, 2003

OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a, *

Timeline

  • Sep 30, 2003 CVE Published
  • Feb 4, 2022 EPSS Score
  • May 21, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 4, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
  • Oct 16, 2023 EPSS Score
  • Dec 24, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›