bugzilla.redhat.comConfirmation
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=104893 CVE-2003-0543
OpenSSL ASN.1 < 0.9.6j/0.9.7b - Brute Forcer for Parsing Bugs
Record summary
CVE-2003-0543 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenSSL ASN.1 < 0.9.6j/0.9.7b - Brute Forcer for Parsing BugsExploitDB exploitby Bram MatthysNot analyzed1 file
References
Showing 12 of 1722249Third-party advisory
http://secunia.com/advisories/22249 201029Vendor advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201029-1 www-1.ibm.comConfirmation
http://www-1.ibm.com/support/docview.wss?uid=swg21247112 CA-2003-26Third-party advisory
http://www.cert.org/advisories/CA-2003-26.html DSA-393Vendor advisory
http://www.debian.org/security/2003/dsa-393 DSA-394Vendor advisory
http://www.debian.org/security/2003/dsa-394 VU#255484Third-party advisory
http://www.kb.cert.org/vuls/id/255484 ESA-20030930-027Vendor advisory
http://www.linuxsecurity.com/advisories/engarde_advisory-3693.html RHSA-2003:291Vendor advisory
http://www.redhat.com/support/errata/RHSA-2003-291.html RHSA-2003:292Vendor advisory
http://www.redhat.com/support/errata/RHSA-2003-292.html 8732vdb entry
http://www.securityfocus.com/bid/8732