RSS   Vulnerabilities for 'Servercluster'   RSS

2004-11-23
 
CVE-2004-0112

CWE-Other
 

 
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

 
 
CVE-2004-0081

CWE-Other
 

 
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

 
 
CVE-2004-0079

CWE-Other
 

 
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

 

 >>> Vendor: Stonesoft 9 Products
Servercluster
Stonebeat fullcluster
Stonebeat securitycluster
Stonebeat webcluster
Stonegate
Stonegate vpn client
Firewall engine
Stonegate firewall
Stonegate ips


Copyright 2024, cxsecurity.com

 

Back to Top