CVE-2004-0112 : Detail

CVE-2004-0112

Overflow
0.7%V4
Network
2004-03-18
04h00 +00:00
2017-10-09
22h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.

Metrics

Metrics Score Severity CVSS Vector Source
V2 5 AV:N/AC:L/Au:N/C:N/I:N/A:P nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Cisco>>Firewall_services_module >> Version *

Cisco>>Firewall_services_module >> Version 1.1.2

Cisco>>Firewall_services_module >> Version 1.1.3

Cisco>>Firewall_services_module >> Version 1.1_\(3.005\)

Cisco>>Firewall_services_module >> Version 2.1_\(0.208\)

Hp>>Aaa_server >> Version *

Hp>>Apache-based_web_server >> Version 2.0.43.00

Hp>>Apache-based_web_server >> Version 2.0.43.04

Symantec>>Clientless_vpn_gateway_4400 >> Version 5.0

Configuraton 0

Cisco>>Ciscoworks_common_management_foundation >> Version 2.1

Cisco>>Ciscoworks_common_services >> Version 2.2

Avaya>>Converged_communications_server >> Version 2.0

Avaya>>Sg200 >> Version 4.4

Avaya>>Sg200 >> Version 4.31.29

Avaya>>Sg203 >> Version 4.4

Avaya>>Sg203 >> Version 4.31.29

Avaya>>Sg208 >> Version *

Avaya>>Sg208 >> Version 4.4

Avaya>>Sg5 >> Version 4.2

Avaya>>Sg5 >> Version 4.3

Avaya>>Sg5 >> Version 4.4

Apple>>Mac_os_x >> Version 10.3.3

Apple>>Mac_os_x_server >> Version 10.3.3

Freebsd>>Freebsd >> Version 4.8

Freebsd>>Freebsd >> Version 4.8

Freebsd>>Freebsd >> Version 4.9

Freebsd>>Freebsd >> Version 5.1

Freebsd>>Freebsd >> Version 5.1

Freebsd>>Freebsd >> Version 5.1

Freebsd>>Freebsd >> Version 5.2

Freebsd>>Freebsd >> Version 5.2.1

Hp>>Hp-ux >> Version 8.05

Hp>>Hp-ux >> Version 11.00

Hp>>Hp-ux >> Version 11.11

Hp>>Hp-ux >> Version 11.23

Openbsd>>Openbsd >> Version 3.3

Openbsd>>Openbsd >> Version 3.4

Redhat>>Enterprise_linux >> Version 3.0

Redhat>>Enterprise_linux >> Version 3.0

Redhat>>Enterprise_linux >> Version 3.0

Redhat>>Enterprise_linux_desktop >> Version 3.0

Redhat>>Linux >> Version 7.2

Redhat>>Linux >> Version 7.3

Redhat>>Linux >> Version 8.0

Sco>>Openserver >> Version 5.0.6

Sco>>Openserver >> Version 5.0.7

Configuraton 0

Cisco>>Ios >> Version 12.1\(11\)e

Cisco>>Ios >> Version 12.1\(11b\)e

Cisco>>Ios >> Version 12.1\(11b\)e12

Cisco>>Ios >> Version 12.1\(11b\)e14

Cisco>>Ios >> Version 12.1\(13\)e9

Cisco>>Ios >> Version 12.1\(19\)e1

Cisco>>Ios >> Version 12.2\(14\)sy

Cisco>>Ios >> Version 12.2\(14\)sy1

Cisco>>Ios >> Version 12.2sy

Cisco>>Ios >> Version 12.2za

4d>>Webstar >> Version 4.0

4d>>Webstar >> Version 5.2

4d>>Webstar >> Version 5.2.1

4d>>Webstar >> Version 5.2.2

4d>>Webstar >> Version 5.2.3

4d>>Webstar >> Version 5.2.4

4d>>Webstar >> Version 5.3

4d>>Webstar >> Version 5.3.1

Avaya>>Intuity_audix >> Version *

Avaya>>Intuity_audix >> Version 5.1.46

Avaya>>Intuity_audix >> Version s3210

Avaya>>Intuity_audix >> Version s3400

Avaya>>Vsu >> Version 5

Avaya>>Vsu >> Version 5x

Avaya>>Vsu >> Version 100_r2.0.1

Avaya>>Vsu >> Version 500

Avaya>>Vsu >> Version 2000_r2.0.1

Avaya>>Vsu >> Version 5000_r2.0.1

Avaya>>Vsu >> Version 7500_r2.0.1

Avaya>>Vsu >> Version 10000_r2.0.1

Checkpoint>>Firewall-1 >> Version *

Checkpoint>>Firewall-1 >> Version 2.0

Checkpoint>>Firewall-1 >> Version next_generation_fp0

Checkpoint>>Firewall-1 >> Version next_generation_fp1

Checkpoint>>Firewall-1 >> Version next_generation_fp2

Checkpoint>>Provider-1 >> Version 4.1

Checkpoint>>Provider-1 >> Version 4.1

Checkpoint>>Provider-1 >> Version 4.1

Checkpoint>>Provider-1 >> Version 4.1

Checkpoint>>Provider-1 >> Version 4.1

Checkpoint>>Vpn-1 >> Version next_generation_fp0

Checkpoint>>Vpn-1 >> Version next_generation_fp1

Checkpoint>>Vpn-1 >> Version next_generation_fp2

Checkpoint>>Vpn-1 >> Version vsx_ng_with_application_intelligence

Cisco>>Access_registrar >> Version *

Cisco>>Application_and_content_networking_software >> Version *

Cisco>>Css_secure_content_accelerator >> Version 1.0

Cisco>>Css_secure_content_accelerator >> Version 2.0

Cisco>>Css11000_content_services_switch >> Version *

Cisco>>Okena_stormwatch >> Version 3.2

Cisco>>Pix_firewall >> Version 6.2.2_.111

Cisco>>Threat_response >> Version *

Cisco>>Webns >> Version 6.10

Cisco>>Webns >> Version 6.10_b4

Cisco>>Webns >> Version 7.1_0.1.02

Cisco>>Webns >> Version 7.1_0.2.06

Cisco>>Webns >> Version 7.2_0.0.03

Cisco>>Webns >> Version 7.10

Cisco>>Webns >> Version 7.10_.0.06s

Dell>>Bsafe_ssl-j >> Version 3.0

Dell>>Bsafe_ssl-j >> Version 3.0.1

Dell>>Bsafe_ssl-j >> Version 3.1

Forcepoint>>Stonegate >> Version 1.5.17

Forcepoint>>Stonegate >> Version 1.5.18

Forcepoint>>Stonegate >> Version 1.6.2

Forcepoint>>Stonegate >> Version 1.6.3

Forcepoint>>Stonegate >> Version 1.7

Forcepoint>>Stonegate >> Version 1.7.1

Forcepoint>>Stonegate >> Version 1.7.2

Forcepoint>>Stonegate >> Version 2.0.1

Forcepoint>>Stonegate >> Version 2.0.4

Forcepoint>>Stonegate >> Version 2.0.5

Forcepoint>>Stonegate >> Version 2.0.6

Forcepoint>>Stonegate >> Version 2.0.7

Forcepoint>>Stonegate >> Version 2.0.8

Forcepoint>>Stonegate >> Version 2.0.9

Forcepoint>>Stonegate >> Version 2.1

Forcepoint>>Stonegate >> Version 2.2

Forcepoint>>Stonegate >> Version 2.2.1

Forcepoint>>Stonegate >> Version 2.2.4

Hp>>Wbem >> Version a.01.05.08

Hp>>Wbem >> Version a.02.00.00

Hp>>Wbem >> Version a.02.00.01

Litespeedtech>>Litespeed_web_server >> Version 1.0.1

Litespeedtech>>Litespeed_web_server >> Version 1.0.2

Litespeedtech>>Litespeed_web_server >> Version 1.0.3

Litespeedtech>>Litespeed_web_server >> Version 1.1

Litespeedtech>>Litespeed_web_server >> Version 1.1.1

Litespeedtech>>Litespeed_web_server >> Version 1.2

Litespeedtech>>Litespeed_web_server >> Version 1.2

Litespeedtech>>Litespeed_web_server >> Version 1.2.1

Litespeedtech>>Litespeed_web_server >> Version 1.2.2

Litespeedtech>>Litespeed_web_server >> Version 1.3

Litespeedtech>>Litespeed_web_server >> Version 1.3

Litespeedtech>>Litespeed_web_server >> Version 1.3

Litespeedtech>>Litespeed_web_server >> Version 1.3

Neoteris>>Instant_virtual_extranet >> Version 3.0

Neoteris>>Instant_virtual_extranet >> Version 3.1

Neoteris>>Instant_virtual_extranet >> Version 3.2

Neoteris>>Instant_virtual_extranet >> Version 3.3

Neoteris>>Instant_virtual_extranet >> Version 3.3.1

Novell>>Edirectory >> Version 8.0

Novell>>Edirectory >> Version 8.5

Novell>>Edirectory >> Version 8.5.12a

Novell>>Edirectory >> Version 8.5.27

Novell>>Edirectory >> Version 8.6.2

Novell>>Edirectory >> Version 8.7

Novell>>Edirectory >> Version 8.7.1

Novell>>Edirectory >> Version 8.7.1

Novell>>Imanager >> Version 1.5

Novell>>Imanager >> Version 2.0

Openssl>>Openssl >> Version 0.9.6c

Openssl>>Openssl >> Version 0.9.6d

Openssl>>Openssl >> Version 0.9.6e

Openssl>>Openssl >> Version 0.9.6f

Openssl>>Openssl >> Version 0.9.6g

Openssl>>Openssl >> Version 0.9.6h

Openssl>>Openssl >> Version 0.9.6i

Openssl>>Openssl >> Version 0.9.6j

Openssl>>Openssl >> Version 0.9.6k

Openssl>>Openssl >> Version 0.9.7

Openssl>>Openssl >> Version 0.9.7

Openssl>>Openssl >> Version 0.9.7

Openssl>>Openssl >> Version 0.9.7

Openssl>>Openssl >> Version 0.9.7a

Openssl>>Openssl >> Version 0.9.7b

Openssl>>Openssl >> Version 0.9.7c

Redhat>>Openssl >> Version 0.9.6-15

Redhat>>Openssl >> Version 0.9.6b-3

Redhat>>Openssl >> Version 0.9.7a-2

Redhat>>Openssl >> Version 0.9.7a-2

Redhat>>Openssl >> Version 0.9.7a-2

Sgi>>Propack >> Version 2.3

Sgi>>Propack >> Version 2.4

Sgi>>Propack >> Version 3.0

Stonesoft>>Servercluster >> Version 2.5

Stonesoft>>Servercluster >> Version 2.5.2

Stonesoft>>Stonebeat_fullcluster >> Version 1_2.0

Stonesoft>>Stonebeat_fullcluster >> Version 1_3.0

Stonesoft>>Stonebeat_fullcluster >> Version 2.0

Stonesoft>>Stonebeat_fullcluster >> Version 2.5

Stonesoft>>Stonebeat_fullcluster >> Version 3.0

Stonesoft>>Stonebeat_securitycluster >> Version 2.0

Stonesoft>>Stonebeat_securitycluster >> Version 2.5

Stonesoft>>Stonebeat_webcluster >> Version 2.0

Stonesoft>>Stonebeat_webcluster >> Version 2.5

Tarantella>>Tarantella_enterprise >> Version 3.20

Tarantella>>Tarantella_enterprise >> Version 3.30

Tarantella>>Tarantella_enterprise >> Version 3.40

Vmware>>Gsx_server >> Version 2.0

Vmware>>Gsx_server >> Version 2.0.1_build_2129

Vmware>>Gsx_server >> Version 2.5.1

Vmware>>Gsx_server >> Version 2.5.1_build_5336

Vmware>>Gsx_server >> Version 3.0_build_7592

Avaya>>S8300 >> Version r2.0.0

Avaya>>S8300 >> Version r2.0.1

Avaya>>S8500 >> Version r2.0.0

Avaya>>S8500 >> Version r2.0.1

Avaya>>S8700 >> Version r2.0.0

Avaya>>S8700 >> Version r2.0.1

Bluecoat>>Proxysg >> Version *

Cisco>>Call_manager >> Version *

Cisco>>Content_services_switch_11500 >> Version *

Cisco>>Gss_4480_global_site_selector >> Version *

Cisco>>Gss_4490_global_site_selector >> Version *

Cisco>>Mds_9000 >> Version *

Cisco>>Secure_content_accelerator >> Version 10000

Securecomputing>>Sidewinder >> Version 5.2

Securecomputing>>Sidewinder >> Version 5.2.0.01

Securecomputing>>Sidewinder >> Version 5.2.0.02

Securecomputing>>Sidewinder >> Version 5.2.0.03

Securecomputing>>Sidewinder >> Version 5.2.0.04

Securecomputing>>Sidewinder >> Version 5.2.1

Securecomputing>>Sidewinder >> Version 5.2.1.02

Sun>>Crypto_accelerator_4000 >> Version 1.0

Bluecoat>>Cacheos_ca_sa >> Version 4.1.10

Bluecoat>>Cacheos_ca_sa >> Version 4.1.12

Cisco>>Pix_firewall_software >> Version 6.0

Cisco>>Pix_firewall_software >> Version 6.0\(1\)

Cisco>>Pix_firewall_software >> Version 6.0\(2\)

Cisco>>Pix_firewall_software >> Version 6.0\(3\)

Cisco>>Pix_firewall_software >> Version 6.0\(4\)

Cisco>>Pix_firewall_software >> Version 6.0\(4.101\)

Cisco>>Pix_firewall_software >> Version 6.1

Cisco>>Pix_firewall_software >> Version 6.1\(1\)

Cisco>>Pix_firewall_software >> Version 6.1\(2\)

Cisco>>Pix_firewall_software >> Version 6.1\(3\)

Cisco>>Pix_firewall_software >> Version 6.1\(4\)

Cisco>>Pix_firewall_software >> Version 6.1\(5\)

Cisco>>Pix_firewall_software >> Version 6.2

Cisco>>Pix_firewall_software >> Version 6.2\(1\)

Cisco>>Pix_firewall_software >> Version 6.2\(2\)

Cisco>>Pix_firewall_software >> Version 6.2\(3\)

Cisco>>Pix_firewall_software >> Version 6.2\(3.100\)

Cisco>>Pix_firewall_software >> Version 6.3

Cisco>>Pix_firewall_software >> Version 6.3\(1\)

Cisco>>Pix_firewall_software >> Version 6.3\(2\)

Cisco>>Pix_firewall_software >> Version 6.3\(3.102\)

Cisco>>Pix_firewall_software >> Version 6.3\(3.109\)

References

http://www.securityfocus.com/bid/9899
Tags : vdb-entry, x_refsource_BID
http://marc.info/?l=bugtraq&m=108403806509920&w=2
Tags : vendor-advisory, x_refsource_HP
http://www.redhat.com/support/errata/RHSA-2004-121.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.mandriva.com/security/advisories?name=MDKSA-2004:023
Tags : vendor-advisory, x_refsource_MANDRAKE
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
Tags : vendor-advisory, x_refsource_CONECTIVA
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
Tags : vendor-advisory, x_refsource_SUNALERT
http://www.ciac.org/ciac/bulletins/o-101.shtml
Tags : third-party-advisory, government-resource, x_refsource_CIAC
http://www.us-cert.gov/cas/techalerts/TA04-078A.html
Tags : third-party-advisory, x_refsource_CERT
http://www.kb.cert.org/vuls/id/484726
Tags : third-party-advisory, x_refsource_CERT-VN
http://security.gentoo.org/glsa/glsa-200403-03.xml
Tags : vendor-advisory, x_refsource_GENTOO
http://secunia.com/advisories/11139
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.redhat.com/support/errata/RHSA-2004-120.html
Tags : vendor-advisory, x_refsource_REDHAT
http://marc.info/?l=bugtraq&m=107953412903636&w=2
Tags : mailing-list, x_refsource_BUGTRAQ
http://www.trustix.org/errata/2004/0012
Tags : vendor-advisory, x_refsource_TRUSTIX