CVE-2007-4995

OpenSSL 0.9.8 - Remote Code Execution via DTLS Off-by-One Error

Title source: llm
STIX 2.1

Description

Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.

References (31)

Core 31
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/482167/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28084
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27271
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27363
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30852
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1571
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27205
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37185
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26055
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200710-30.xml
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30220
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:237
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/4219
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10288
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27217
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0964.html
Issue Tracking x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=195634
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30161
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27434
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3487
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25878
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018810
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1937/references
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/534-1/
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27933

Scores

EPSS 0.1062
EPSS Percentile 93.4%

Details

CWE
CWE-189
Status published
Products (6)
openssl/openssl 0.9.8
openssl/openssl 0.9.8a
openssl/openssl 0.9.8b
openssl/openssl 0.9.8c
openssl/openssl 0.9.8d
openssl/openssl 0.9.8e
Published Oct 13, 2007
Tracked Since Feb 18, 2026