CVE-2004-0112 PUBLISHED CVSS 5 MEDIUM

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

EPSS 1.85% · 82.9th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
1.85%
82.9th percentile

Affected Products

VendorProductVersions
tarantellatarantella_enterprise3.40, 3.30, 3.20
n/an/an/a
novelledirectory8.5.12a, 8.5.27, 8.6.2
securecomputingsidewinder5.2.0.04, 5.2.1.02, 5.2.1
ciscogss_4490_global_site_selector
stonesoftstonebeat_securitycluster2.0, 2.5
bluecoatcacheos_ca_sa4.1.12, 4.1.10
avayas8700r2.0.0, r2.0.1
redhatopenssl0.9.7a-2, 0.9.7a-2, 0.9.7a-2
suncrypto_accelerator_40001.0
ciscociscoworks_common_management_foundation2.1
avayasg54.2, 4.3, 4.4
stonesoftservercluster2.5.2, 2.5
novellimanager2.0, 1.5
ciscocall_manager
ciscoaccess_registrar
avayasg2034.31.29, 4.4
ciscookena_stormwatch3.2
ciscopix_firewall_software6.2\(2\), 6.2\(3\), 6.2\(3.100\)
forcepointstonegate1.6.2, 1.5.17, 1.5.18

…and 46 more

Timeline

References

…and 10 more

Open in Interactive Console →