漏洞信息详情
OpenSSL SSLv2 Client_Master_Key远程拒绝服务漏洞
- CNNVD编号:CNNVD-200311-080
- 危害等级: 中危
- CVE编号:
CVE-2002-1568
- 漏洞类型:
缓冲区溢出
- 发布时间:
2003-11-17
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
openssl - 漏洞来源:
Discovery of this … -
漏洞简介
OpenSSL 0.9.6e版本使用断言检测缓冲区溢出攻击而不是较少严重机制溢出攻击。远程攻击者借助致使OpenSSL中止失败断言的某些消息导致服务拒绝(崩溃),正如使用没有正确处理s2_srvr.c的SSLv2 CLIENT_MASTER_KEY消息。
漏洞公告
OpenSSL have reportedly addressed this issue in versions 0.9.6f and greater.
Red Hat has reportedly addressed this issue in the RHSA-2003:291-11 advisory. See referenced advisory for further information relating to obtaining and applying fixes.
Guardian Digital has released an advisory for EnGarde (ESA-20031003-028) to address this issue. Updates may be applied with the Guardian Digital WebTool. Further details may be found in the attached advisory.
VMware has released fixes to address this issue. Please see the related web reference for more information.
IBM has released fixes to address these issues in IBM HTTP Server.
OpenSSL Project OpenSSL 0.9.6 d
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 c
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6
-
Engarde Secure Linux openssl-0.9.6-1.0.21.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-0.9.6-1.0.21.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-devel-0.9.6-1.0.21.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-devel-0.9.6-1.0.21.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-misc-0.9.6-1.0.21.i386.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
Engarde Secure Linux openssl-misc-0.9.6-1.0.21.i686.rpm
ftp://ftp.engardelinux.org/pub/engarde/ -
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 b
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 e
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
OpenSSL Project OpenSSL 0.9.6 a
-
OpenSSL Project OpenSSL 0.9.6k
http://www.openssl.org/source/
IBM HTTP Server 1.3.12 .7
IBM HTTP Server 1.3.12 .2
IBM HTTP Server 1.3.12 .6
IBM HTTP Server 1.3.12 .1
IBM HTTP Server 1.3.12 .3
IBM HTTP Server 1.3.12
IBM HTTP Server 1.3.12 .5
IBM HTTP Server 1.3.12 .4
IBM HTTP Server 1.3.19 .1
IBM HTTP Server 1.3.19 .3
IBM HTTP Server 1.3.19 .4
IBM HTTP Server 1.3.19
IBM HTTP Server 1.3.19 .5
IBM HTTP Server 1.3.19 .2
IBM HTTP Server 1.3.26
IBM HTTP Server 1.3.26 .2
IBM HTTP Server 1.3.26 .1
IBM HTTP Server 1.3.28
参考网址
来源: cvs.openssl.org
链接:http://cvs.openssl.org/chngview?cn=7659
来源: www.ebitech.sk
链接:http://www.ebitech.sk/patrik/SA/SA-20031002.txt
来源: BUGTRAQ
名称: 20031002 New OpenSSL remote vulnerability (issue date 2003/10/02)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106511018214983