Bug 1254 - Denial of Service vulnerabilities in OpenSSL
: Denial of Service vulnerabilities in OpenSSL
Status: RESOLVED FIXED
: GSI C
Credentials and Proxies
: unspecified
: PC Linux
: P2 normal
: ---
Assigned To:
:
:
:
:
  Show dependency treegraph
 
Reported: 2003-10-02 00:04 by
Modified: 2008-08-11 13:54 (History)


Attachments


Note

You need to log in before you can comment on or make changes to this bug.


Description From 2003-10-02 00:04:11
The OpenSSL project has recently published a report detailing several problems
with the OpenSSL ASN.1 handling:

http://www.openssl.org/news/secadv_20030930.txt

These problems can be exploited for denial of service attacks against
servers/services using the older openssl source release. To the best of our
knowledge there bugs can not be used to gain unauthorized access to systems
running the problematic code.
------- Comment #1 From 2003-10-02 00:16:46 -------
Update packages are now available.