Secunia Logo
 
CVE Reference: CVE-2003-0544
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2003-0544

Description:
OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/43041

VULNWATCH

SAID
  Secunia Advisory: SA22249

REDHAT
  http://www.redhat.com/support/errata/RHSA-2003-291.html
  http://www.redhat.com/support/errata/RHSA-2003-292.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4574

MISC
  http://www.uniras.gov.uk/vuls/2003/006489/openssl.htm

FULLDISC

ENGARDE
  http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html

DEBIAN
  http://www.debian.org/security/2003/dsa-393
  http://www.debian.org/security/2003/dsa-394

CONFIRM
  http://www-1.ibm.com/support/docview.wss?uid=swg21247112
  http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893

CERT-VN
  380864

CERT
  http://www.cert.org/advisories/CA-2003-26.html

BID
  8732


Return to the previous page.