|
|
Log in / Subscribe / Register

openssl: off-by-one error

Package(s):openssl CVE #(s):CVE-2007-5135
Created:October 3, 2007 Updated:July 31, 2008
Description: From the Debian advisory: An off-by-one error has been identified in the SSL_get_shared_ciphers() routine in the libssl library from OpenSSL, an implementation of Secure Socket Layer cryptographic libraries and utilities. This error could allow an attacker to crash an application making use of OpenSSL's libssl library, or potentially execute arbitrary code in the security context of the user running such an application.
Alerts:
Gentoo 201412-11 emul-linux-x86-baselibs 2014-12-11
rPath rPSA-2008-0241-1 openssl 2008-07-30
SuSE SUSE-SR:2008:005 acroread, asterisk, cacti, compat-openssl097g, icu, libcdio, wireshark/ethereal, Jakarta, perl-tk 2008-03-06
Red Hat RHSA-2007:1003-02 OpenSSL 2007-11-15
Red Hat RHSA-2007:0813-01 OpenSSL 2007-10-22
Fedora FEDORA-2007-2530 openssl 2007-10-18
Fedora FEDORA-2007-725 openssl 2007-10-15
SuSE SUSE-SR:2007:020 TK, openssl, hugin, lighttpd, novell-groupwise-gwclient, sylpheed-claws 2007-10-12
Red Hat RHSA-2007:0964-01 OpenSSL 2007-10-12
Debian DSA-1379-2 openssl097 2007-10-10
Gentoo 200710-06 openssl 2007-10-07
Mandriva MDKSA-2007:193 openssl 2007-10-04
rPath rPSA-2007-0206-1 openssl 2007-10-03
Foresight FLEA-2007-0058-1 dist 2007-10-03
Debian DSA-1379 openssl 2007-10-02

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds