CVE-2004-0112 : Detail

CVE-2004-0112

Overflow
0.94%V4
Network
2004-03-18
04h00 +00:00
2017-10-09
22h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.

Metrics

Metrics Score Severity CVSS Vector Source
V2 5 AV:N/AC:L/Au:N/C:N/I:N/A:P nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Cisco>>Firewall_services_module >> Version *

Cisco>>Firewall_services_module >> Version 1.1.2

Cisco>>Firewall_services_module >> Version 1.1.3

Cisco>>Firewall_services_module >> Version 1.1_\(3.005\)

Cisco>>Firewall_services_module >> Version 2.1_\(0.208\)

Hp>>Aaa_server >> Version *

Hp>>Apache-based_web_server >> Version 2.0.43.00

Hp>>Apache-based_web_server >> Version 2.0.43.04

Symantec>>Clientless_vpn_gateway_4400 >> Version 5.0

Configuraton 0

Cisco>>Ciscoworks_common_management_foundation >> Version 2.1

Cisco>>Ciscoworks_common_services >> Version 2.2

Avaya>>Converged_communications_server >> Version 2.0

Avaya>>Sg200 >> Version 4.4

Avaya>>Sg200 >> Version 4.31.29

Avaya>>Sg203 >> Version 4.4

Avaya>>Sg203 >> Version 4.31.29

Avaya>>Sg208 >> Version *

Avaya>>Sg208 >> Version 4.4

Avaya>>Sg5 >> Version 4.2

Avaya>>Sg5 >> Version 4.3

Avaya>>Sg5 >> Version 4.4

Apple>>Mac_os_x >> Version 10.3.3

Apple>>Mac_os_x_server >> Version 10.3.3

Freebsd>>Freebsd >> Version 4.8

Freebsd>>Freebsd >> Version 4.8

    Freebsd>>Freebsd >> Version 4.9

    Freebsd>>Freebsd >> Version 5.1

    Freebsd>>Freebsd >> Version 5.1

      Freebsd>>Freebsd >> Version 5.1

        Freebsd>>Freebsd >> Version 5.2

        Freebsd>>Freebsd >> Version 5.2.1

          Hp>>Hp-ux >> Version 8.05

          Hp>>Hp-ux >> Version 11.00

          Hp>>Hp-ux >> Version 11.11

          Hp>>Hp-ux >> Version 11.23

          Openbsd>>Openbsd >> Version 3.3

          Openbsd>>Openbsd >> Version 3.4

          Redhat>>Enterprise_linux >> Version 3.0

          Redhat>>Enterprise_linux >> Version 3.0

          Redhat>>Enterprise_linux >> Version 3.0

          Redhat>>Enterprise_linux_desktop >> Version 3.0

          Redhat>>Linux >> Version 7.2

          Redhat>>Linux >> Version 7.3

          Redhat>>Linux >> Version 8.0

          Sco>>Openserver >> Version 5.0.6

          Sco>>Openserver >> Version 5.0.7

          Configuraton 0

          Cisco>>Ios >> Version 12.1\(11\)e

          Cisco>>Ios >> Version 12.1\(11b\)e

          Cisco>>Ios >> Version 12.1\(11b\)e12

          Cisco>>Ios >> Version 12.1\(11b\)e14

          Cisco>>Ios >> Version 12.1\(13\)e9

          Cisco>>Ios >> Version 12.1\(19\)e1

          Cisco>>Ios >> Version 12.2\(14\)sy

          Cisco>>Ios >> Version 12.2\(14\)sy1

          Cisco>>Ios >> Version 12.2sy

          Cisco>>Ios >> Version 12.2za

          4d>>Webstar >> Version 4.0

          4d>>Webstar >> Version 5.2

          4d>>Webstar >> Version 5.2.1

          4d>>Webstar >> Version 5.2.2

          4d>>Webstar >> Version 5.2.3

          4d>>Webstar >> Version 5.2.4

          4d>>Webstar >> Version 5.3

          4d>>Webstar >> Version 5.3.1

          Avaya>>Intuity_audix >> Version *

            Avaya>>Intuity_audix >> Version 5.1.46

            Avaya>>Intuity_audix >> Version s3210

              Avaya>>Intuity_audix >> Version s3400

                Avaya>>Vsu >> Version 5

                Avaya>>Vsu >> Version 5x

                Avaya>>Vsu >> Version 100_r2.0.1

                Avaya>>Vsu >> Version 500

                Avaya>>Vsu >> Version 2000_r2.0.1

                Avaya>>Vsu >> Version 5000_r2.0.1

                Avaya>>Vsu >> Version 7500_r2.0.1

                Avaya>>Vsu >> Version 10000_r2.0.1

                Checkpoint>>Firewall-1 >> Version *

                  Checkpoint>>Firewall-1 >> Version 2.0

                    Checkpoint>>Firewall-1 >> Version next_generation_fp0

                      Checkpoint>>Firewall-1 >> Version next_generation_fp1

                        Checkpoint>>Firewall-1 >> Version next_generation_fp2

                          Checkpoint>>Provider-1 >> Version 4.1

                          Checkpoint>>Provider-1 >> Version 4.1

                          Checkpoint>>Provider-1 >> Version 4.1

                          Checkpoint>>Provider-1 >> Version 4.1

                          Checkpoint>>Provider-1 >> Version 4.1

                          Checkpoint>>Vpn-1 >> Version next_generation_fp0

                            Checkpoint>>Vpn-1 >> Version next_generation_fp1

                              Checkpoint>>Vpn-1 >> Version next_generation_fp2

                                Checkpoint>>Vpn-1 >> Version vsx_ng_with_application_intelligence

                                  Cisco>>Access_registrar >> Version *

                                  Cisco>>Application_and_content_networking_software >> Version *

                                  Cisco>>Css_secure_content_accelerator >> Version 1.0

                                    Cisco>>Css_secure_content_accelerator >> Version 2.0

                                      Cisco>>Css11000_content_services_switch >> Version *

                                        Cisco>>Okena_stormwatch >> Version 3.2

                                        Cisco>>Pix_firewall >> Version 6.2.2_.111

                                          Cisco>>Threat_response >> Version *

                                          Cisco>>Webns >> Version 6.10

                                          Cisco>>Webns >> Version 6.10_b4

                                          Cisco>>Webns >> Version 7.1_0.1.02

                                          Cisco>>Webns >> Version 7.1_0.2.06

                                          Cisco>>Webns >> Version 7.2_0.0.03

                                          Cisco>>Webns >> Version 7.10

                                          Cisco>>Webns >> Version 7.10_.0.06s

                                          Dell>>Bsafe_ssl-j >> Version 3.0

                                          Dell>>Bsafe_ssl-j >> Version 3.0.1

                                          Dell>>Bsafe_ssl-j >> Version 3.1

                                          Forcepoint>>Stonegate >> Version 1.5.17

                                          Forcepoint>>Stonegate >> Version 1.5.18

                                          Forcepoint>>Stonegate >> Version 1.6.2

                                          Forcepoint>>Stonegate >> Version 1.6.3

                                          Forcepoint>>Stonegate >> Version 1.7

                                          Forcepoint>>Stonegate >> Version 1.7.1

                                          Forcepoint>>Stonegate >> Version 1.7.2

                                          Forcepoint>>Stonegate >> Version 2.0.1

                                          Forcepoint>>Stonegate >> Version 2.0.4

                                          Forcepoint>>Stonegate >> Version 2.0.5

                                          Forcepoint>>Stonegate >> Version 2.0.6

                                          Forcepoint>>Stonegate >> Version 2.0.7

                                          Forcepoint>>Stonegate >> Version 2.0.8

                                          Forcepoint>>Stonegate >> Version 2.0.9

                                          Forcepoint>>Stonegate >> Version 2.1

                                          Forcepoint>>Stonegate >> Version 2.2

                                          Forcepoint>>Stonegate >> Version 2.2.1

                                          Forcepoint>>Stonegate >> Version 2.2.4

                                          Hp>>Wbem >> Version a.01.05.08

                                          Hp>>Wbem >> Version a.02.00.00

                                          Hp>>Wbem >> Version a.02.00.01

                                          Litespeedtech>>Litespeed_web_server >> Version 1.0.1

                                          Litespeedtech>>Litespeed_web_server >> Version 1.0.2

                                          Litespeedtech>>Litespeed_web_server >> Version 1.0.3

                                          Litespeedtech>>Litespeed_web_server >> Version 1.1

                                          Litespeedtech>>Litespeed_web_server >> Version 1.1.1

                                          Litespeedtech>>Litespeed_web_server >> Version 1.2

                                          Litespeedtech>>Litespeed_web_server >> Version 1.2

                                          Litespeedtech>>Litespeed_web_server >> Version 1.2.1

                                          Litespeedtech>>Litespeed_web_server >> Version 1.2.2

                                          Litespeedtech>>Litespeed_web_server >> Version 1.3

                                          Litespeedtech>>Litespeed_web_server >> Version 1.3

                                          Litespeedtech>>Litespeed_web_server >> Version 1.3

                                          Litespeedtech>>Litespeed_web_server >> Version 1.3

                                          Neoteris>>Instant_virtual_extranet >> Version 3.0

                                            Neoteris>>Instant_virtual_extranet >> Version 3.1

                                              Neoteris>>Instant_virtual_extranet >> Version 3.2

                                                Neoteris>>Instant_virtual_extranet >> Version 3.3

                                                  Neoteris>>Instant_virtual_extranet >> Version 3.3.1

                                                    Novell>>Edirectory >> Version 8.0

                                                    Novell>>Edirectory >> Version 8.5

                                                    Novell>>Edirectory >> Version 8.5.12a

                                                    Novell>>Edirectory >> Version 8.5.27

                                                    Novell>>Edirectory >> Version 8.6.2

                                                    Novell>>Edirectory >> Version 8.7

                                                    Novell>>Edirectory >> Version 8.7.1

                                                    Novell>>Edirectory >> Version 8.7.1

                                                    Novell>>Imanager >> Version 1.5

                                                    Novell>>Imanager >> Version 2.0

                                                    Openssl>>Openssl >> Version 0.9.6c

                                                    Openssl>>Openssl >> Version 0.9.6d

                                                    Openssl>>Openssl >> Version 0.9.6e

                                                    Openssl>>Openssl >> Version 0.9.6f

                                                    Openssl>>Openssl >> Version 0.9.6g

                                                    Openssl>>Openssl >> Version 0.9.6h

                                                    Openssl>>Openssl >> Version 0.9.6i

                                                    Openssl>>Openssl >> Version 0.9.6j

                                                    Openssl>>Openssl >> Version 0.9.6k

                                                    Openssl>>Openssl >> Version 0.9.7

                                                    Openssl>>Openssl >> Version 0.9.7

                                                    Openssl>>Openssl >> Version 0.9.7

                                                    Openssl>>Openssl >> Version 0.9.7

                                                    Openssl>>Openssl >> Version 0.9.7a

                                                    Openssl>>Openssl >> Version 0.9.7b

                                                    Openssl>>Openssl >> Version 0.9.7c

                                                    Redhat>>Openssl >> Version 0.9.6-15

                                                      Redhat>>Openssl >> Version 0.9.6b-3

                                                        Redhat>>Openssl >> Version 0.9.7a-2

                                                          Redhat>>Openssl >> Version 0.9.7a-2

                                                            Redhat>>Openssl >> Version 0.9.7a-2

                                                              Sgi>>Propack >> Version 2.3

                                                              Sgi>>Propack >> Version 2.4

                                                              Sgi>>Propack >> Version 3.0

                                                              Stonesoft>>Servercluster >> Version 2.5

                                                                Stonesoft>>Servercluster >> Version 2.5.2

                                                                  Stonesoft>>Stonebeat_fullcluster >> Version 1_2.0

                                                                    Stonesoft>>Stonebeat_fullcluster >> Version 1_3.0

                                                                      Stonesoft>>Stonebeat_fullcluster >> Version 2.0

                                                                        Stonesoft>>Stonebeat_fullcluster >> Version 2.5

                                                                          Stonesoft>>Stonebeat_fullcluster >> Version 3.0

                                                                            Stonesoft>>Stonebeat_securitycluster >> Version 2.0

                                                                              Stonesoft>>Stonebeat_securitycluster >> Version 2.5

                                                                                Stonesoft>>Stonebeat_webcluster >> Version 2.0

                                                                                  Stonesoft>>Stonebeat_webcluster >> Version 2.5

                                                                                    Tarantella>>Tarantella_enterprise >> Version 3.20

                                                                                      Tarantella>>Tarantella_enterprise >> Version 3.30

                                                                                        Tarantella>>Tarantella_enterprise >> Version 3.40

                                                                                          Vmware>>Gsx_server >> Version 2.0

                                                                                          Vmware>>Gsx_server >> Version 2.0.1_build_2129

                                                                                          Vmware>>Gsx_server >> Version 2.5.1

                                                                                          Vmware>>Gsx_server >> Version 2.5.1_build_5336

                                                                                          Vmware>>Gsx_server >> Version 3.0_build_7592

                                                                                          Avaya>>S8300 >> Version r2.0.0

                                                                                          Avaya>>S8300 >> Version r2.0.1

                                                                                          Avaya>>S8500 >> Version r2.0.0

                                                                                          Avaya>>S8500 >> Version r2.0.1

                                                                                          Avaya>>S8700 >> Version r2.0.0

                                                                                          Avaya>>S8700 >> Version r2.0.1

                                                                                          Bluecoat>>Proxysg >> Version *

                                                                                          Cisco>>Call_manager >> Version *

                                                                                          Cisco>>Content_services_switch_11500 >> Version *

                                                                                          Cisco>>Gss_4480_global_site_selector >> Version *

                                                                                          Cisco>>Gss_4490_global_site_selector >> Version *

                                                                                          Cisco>>Mds_9000 >> Version *

                                                                                          Cisco>>Secure_content_accelerator >> Version 10000

                                                                                            Securecomputing>>Sidewinder >> Version 5.2

                                                                                            Securecomputing>>Sidewinder >> Version 5.2.0.01

                                                                                            Securecomputing>>Sidewinder >> Version 5.2.0.02

                                                                                            Securecomputing>>Sidewinder >> Version 5.2.0.03

                                                                                            Securecomputing>>Sidewinder >> Version 5.2.0.04

                                                                                            Securecomputing>>Sidewinder >> Version 5.2.1

                                                                                            Securecomputing>>Sidewinder >> Version 5.2.1.02

                                                                                            Sun>>Crypto_accelerator_4000 >> Version 1.0

                                                                                            Bluecoat>>Cacheos_ca_sa >> Version 4.1.10

                                                                                              Bluecoat>>Cacheos_ca_sa >> Version 4.1.12

                                                                                                Cisco>>Pix_firewall_software >> Version 6.0

                                                                                                Cisco>>Pix_firewall_software >> Version 6.0\(1\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.0\(2\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.0\(3\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.0\(4\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.0\(4.101\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.1

                                                                                                Cisco>>Pix_firewall_software >> Version 6.1\(1\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.1\(2\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.1\(3\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.1\(4\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.1\(5\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.2

                                                                                                Cisco>>Pix_firewall_software >> Version 6.2\(1\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.2\(2\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.2\(3\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.2\(3.100\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.3

                                                                                                Cisco>>Pix_firewall_software >> Version 6.3\(1\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.3\(2\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.3\(3.102\)

                                                                                                Cisco>>Pix_firewall_software >> Version 6.3\(3.109\)

                                                                                                References

                                                                                                http://www.securityfocus.com/bid/9899
                                                                                                Tags : vdb-entry, x_refsource_BID
                                                                                                http://marc.info/?l=bugtraq&m=108403806509920&w=2
                                                                                                Tags : vendor-advisory, x_refsource_HP
                                                                                                http://www.redhat.com/support/errata/RHSA-2004-121.html
                                                                                                Tags : vendor-advisory, x_refsource_REDHAT
                                                                                                http://www.mandriva.com/security/advisories?name=MDKSA-2004:023
                                                                                                Tags : vendor-advisory, x_refsource_MANDRAKE
                                                                                                http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
                                                                                                Tags : vendor-advisory, x_refsource_CONECTIVA
                                                                                                http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
                                                                                                Tags : vendor-advisory, x_refsource_SUNALERT
                                                                                                http://www.ciac.org/ciac/bulletins/o-101.shtml
                                                                                                Tags : third-party-advisory, government-resource, x_refsource_CIAC
                                                                                                http://www.us-cert.gov/cas/techalerts/TA04-078A.html
                                                                                                Tags : third-party-advisory, x_refsource_CERT
                                                                                                http://www.kb.cert.org/vuls/id/484726
                                                                                                Tags : third-party-advisory, x_refsource_CERT-VN
                                                                                                http://security.gentoo.org/glsa/glsa-200403-03.xml
                                                                                                Tags : vendor-advisory, x_refsource_GENTOO
                                                                                                http://secunia.com/advisories/11139
                                                                                                Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                http://www.redhat.com/support/errata/RHSA-2004-120.html
                                                                                                Tags : vendor-advisory, x_refsource_REDHAT
                                                                                                http://marc.info/?l=bugtraq&m=107953412903636&w=2
                                                                                                Tags : mailing-list, x_refsource_BUGTRAQ
                                                                                                http://www.trustix.org/errata/2004/0012
                                                                                                Tags : vendor-advisory, x_refsource_TRUSTIX