CVE-2008-1672
CVE-2008-1672
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://cert.fi/haavoittuvuudet/2008/advisory-openssl.htmlhttp://secunia.com/advisories/30405http://secunia.com/advisories/30460http://secunia.com/advisories/30825http://secunia.com/advisories/30852http://secunia.com/advisories/30868http://secunia.com/advisories/31228http://secunia.com/advisories/31288http://security.gentoo.org/glsa/glsa-200806-08.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/42667http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.562004http://sourceforge.net/project/shownotes.php?release_id=615606