OpenSSL SSLv2 Client_Master_Key远程拒绝服务漏洞

漏洞信息详情

OpenSSL SSLv2 Client_Master_Key远程拒绝服务漏洞

漏洞简介

OpenSSL 0.9.6e版本使用断言检测缓冲区溢出攻击而不是较少严重机制溢出攻击。远程攻击者借助致使OpenSSL中止失败断言的某些消息导致服务拒绝(崩溃),正如使用没有正确处理s2_srvr.c的SSLv2 CLIENT_MASTER_KEY消息。

漏洞公告

OpenSSL have reportedly addressed this issue in versions 0.9.6f and greater.
Red Hat has reportedly addressed this issue in the RHSA-2003:291-11 advisory. See referenced advisory for further information relating to obtaining and applying fixes.
Guardian Digital has released an advisory for EnGarde (ESA-20031003-028) to address this issue. Updates may be applied with the Guardian Digital WebTool. Further details may be found in the attached advisory.
VMware has released fixes to address this issue. Please see the related web reference for more information.
IBM has released fixes to address these issues in IBM HTTP Server.

OpenSSL Project OpenSSL 0.9.6 d

OpenSSL Project OpenSSL 0.9.6 c

OpenSSL Project OpenSSL 0.9.6

OpenSSL Project OpenSSL 0.9.6 b

OpenSSL Project OpenSSL 0.9.6 e

OpenSSL Project OpenSSL 0.9.6 a

IBM HTTP Server 1.3.12 .7

IBM HTTP Server 1.3.12 .2

IBM HTTP Server 1.3.12 .6

IBM HTTP Server 1.3.12 .1

IBM HTTP Server 1.3.12 .3

IBM HTTP Server 1.3.12

IBM HTTP Server 1.3.12 .5

IBM HTTP Server 1.3.12 .4

IBM HTTP Server 1.3.19 .1

IBM HTTP Server 1.3.19 .3

IBM HTTP Server 1.3.19 .4

IBM HTTP Server 1.3.19

IBM HTTP Server 1.3.19 .5

IBM HTTP Server 1.3.19 .2

IBM HTTP Server 1.3.26

IBM HTTP Server 1.3.26 .2

IBM HTTP Server 1.3.26 .1

IBM HTTP Server 1.3.28

参考网址

来源: cvs.openssl.org
链接:http://cvs.openssl.org/chngview?cn=7659

来源: www.ebitech.sk
链接:http://www.ebitech.sk/patrik/SA/SA-20031002.txt

来源: BUGTRAQ
名称: 20031002 New OpenSSL remote vulnerability (issue date 2003/10/02)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106511018214983

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享