Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2004-0112

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

SeverityMEDIUM
CVSS5.0
CWECWE-125
KEV
Published
Modified

Related Products

Product Advisory Evidence
CiscoWorks Common Services (CS) cisco-sa-20040317-openssl Cisco OpenVuln
CiscoWorks Common Management Foundation (CMF) cisco-sa-20040317-openssl Cisco OpenVuln
Cisco WebNS cisco-sa-20040317-openssl Cisco OpenVuln
Cisco Unified Communications Manager cisco-sa-20040317-openssl Cisco OpenVuln
Cisco PIX Firewall Software cisco-sa-20040317-openssl Cisco OpenVuln
Cisco PIX Firewall cisco-sa-20040317-openssl Cisco OpenVuln
Cisco Okena StormWatch cisco-sa-20040317-openssl Cisco OpenVuln
Cisco MDS SAN-OS Software cisco-sa-20040317-openssl Cisco OpenVuln
Cisco GSS Global Site Selector cisco-sa-20040317-openssl Cisco OpenVuln
Cisco Firewall Services Module (FWSM) cisco-sa-20040317-openssl Cisco OpenVuln
Cisco Application and Content Networking System (ACNS) Software cisco-sa-20040317-openssl Cisco OpenVuln
Application and Content Networking System (ACNS) Software cisco-sa-20040317-openssl Cisco OpenVuln