CVE-2008-0891
CVE-2008-0891
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://cert.fi/haavoittuvuudet/2008/advisory-openssl.htmlhttp://secunia.com/advisories/30405http://secunia.com/advisories/30460http://secunia.com/advisories/30825http://secunia.com/advisories/30852http://secunia.com/advisories/30868http://secunia.com/advisories/31228http://secunia.com/advisories/31288http://security.gentoo.org/glsa/glsa-200806-08.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/42666http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.562004http://sourceforge.net/project/shownotes.php?release_id=615606