Description
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
Affected products
- Cisco / css11000_content_services_switch
- Cisco / IOS12.1(11)e – 12.1(11)e
- Cisco / IOS12.1(11b)e – 12.1(11b)e
- Cisco / IOS12.2sx – 12.2sx
- Cisco / IOS12.2sy – 12.2sy
- Cisco / pix_firewall6.2.2_.111 – 6.2.2_.111
- Cisco / pix_firewall_software6.3(3.102) – 6.3(3.102)
- Cisco / pix_firewall_software6.0(2) – 6.0(2)
- Cisco / pix_firewall_software6.0(3) – 6.0(3)
- Cisco / pix_firewall_software6.0(4) – 6.0(4)
- Cisco / pix_firewall_software6.0(4.101) – 6.0(4.101)
- Cisco / pix_firewall_software6.1 – 6.1
- Cisco / pix_firewall_software6.1(1) – 6.1(1)
- Cisco / pix_firewall_software6.1(2) – 6.1(2)
- Cisco / pix_firewall_software6.1(3) – 6.1(3)
- Cisco / pix_firewall_software6.1(4) – 6.1(4)
- Cisco / pix_firewall_software6.1(5) – 6.1(5)
- Cisco / pix_firewall_software6.2 – 6.2
- Cisco / pix_firewall_software6.2(1) – 6.2(1)
- Cisco / pix_firewall_software6.2(2) – 6.2(2)
- Cisco / pix_firewall_software6.2(3) – 6.2(3)
- Cisco / pix_firewall_software6.3(1) – 6.3(1)
- Cisco / pix_firewall_software6.0 – 6.0
- Cisco / pix_firewall_software6.0(1) – 6.0(1)
- OpenSSL / OpenSSL0.9.6a – 0.9.6a
- OpenSSL / OpenSSL0.9.6b – 0.9.6b
- OpenSSL / OpenSSL0.9.6c – 0.9.6c
- OpenSSL / OpenSSL0.9.6d – 0.9.6d
- OpenSSL / OpenSSL0.9.6e – 0.9.6e
- OpenSSL / OpenSSL0.9.6f – 0.9.6f
- OpenSSL / OpenSSL0.9.6g – 0.9.6g
- OpenSSL / OpenSSL0.9.6h – 0.9.6h
- OpenSSL / OpenSSL0.9.6i – 0.9.6i
- OpenSSL / OpenSSL0.9.6j – 0.9.6j
- OpenSSL / OpenSSL0.9.6k – 0.9.6k
- OpenSSL / OpenSSL0.9.7 – 0.9.7
- OpenSSL / OpenSSL0.9.7a – 0.9.7a
- OpenSSL / OpenSSL0.9.7b – 0.9.7b
- OpenSSL / OpenSSL0.9.6 – 0.9.6
References
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5528
- MISChttp://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc
- VENDOR_ADVISORYhttp://secunia.com/advisories/17381
- VENDOR_ADVISORYftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-003.txt.asc
- VENDOR_ADVISORYhttp://www.cisco.com/warp/public/707/cisco-sa-20030930-ssl.shtml
- MISChttp://www.securityfocus.com/bid/8970
- MAILING_LISThttp://marc.info/?l=bugtraq&m=106796246511667&w=2
- MISChttp://rhn.redhat.com/errata/RHSA-2004-119.html
- MISChttp://www.openssl.org/news/secadv_20031104.txt
- MISChttp://www.kb.cert.org/vuls/id/412478
- MAILING_LISThttp://marc.info/?l=bugtraq&m=108403850228012&w=2