VDB
CVE-2004-0079
CVE-2004-0079
PUBLISHED
CVSS 5 MEDIUM
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
EPSS 9.54% · 95.2th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
9.54%
95.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | mac_os_x | 10.3.3 |
| openbsd | openbsd | 3.4, 3.3 |
| avaya | sg5 | 4.4, 4.3, 4.2 |
| cisco | ciscoworks_common_services | 2.2 |
| securecomputing | sidewinder | 5.2.0.03, 5.2.0.04, 5.2.1 |
| sgi | propack | 3.0, 2.3, 2.4 |
| sun | crypto_accelerator_4000 | 1.0 |
| cisco | application_and_content_networking_software | |
| avaya | s8700 | r2.0.1, * |
| freebsd | freebsd | 5.2, 5.2.1, 4.9 |
| n/a | n/a | n/a |
| stonesoft | stonebeat_webcluster | 2.5, 2.0 |
| redhat | enterprise_linux_desktop | 3.0 |
| avaya | sg208 | 4.4 |
| redhat | enterprise_linux | 3.0, 3.0, 3.0 |
| avaya | s8300 | r2.0.0, * |
| cisco | firewall_services_module | 2.1_\(0.208\), 1.1_\(3.005\), 1.1.3 |
| cisco | pix_firewall_software | 6.0\(2\), 6.0\(1\), 6.0 |
| bluecoat | cacheos_ca_sa | 4.1.12, 4.1.10 |
| avaya | intuity_audix | s3400, 5.1.46, s3210 |
…and 47 more
Timeline
- Jul 18, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- CLA-2004:834 vendor-advisory
- http://www.openssl.org/news/secadv_20040317.txt url
- RHSA-2005:829 vendor-advisory
- RHSA-2005:830 vendor-advisory
- 17398 third-party-advisory
- 20040317 Cisco OpenSSL Implementation Vulnerability vendor-advisory
- oval:org.mitre.oval:def:5770 vdb
- http://www.uniras.gov.uk/vuls/2004/224012/index.htm url
- SuSE-SA:2004:007 vendor-advisory
- http://lists.apple.com/mhonarc/security-announce/msg00045.html url
- NetBSD-SA2004-005 vendor-advisory
- TA04-078A third-party-advisory
- 17401 third-party-advisory
- oval:org.mitre.oval:def:870 vdb
- GLSA-200403-03 vendor-advisory
- http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US url
- SSA:2004-077 vendor-advisory
- VU#288574 third-party-advisory
- APPLE-SA-2005-08-17 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0079 advisory
…and 26 more