HIGH · 7.5

CVE-2004-0079

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null ...

Vulnerability Description

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoFirewall Services ModuleAll versions
HpAaa ServerAll versions
HpApache-Based Web Server2.0.43.00
SymantecClientless Vpn Gateway 44005.0
CiscoCiscoworks Common Management Foundation2.1
CiscoCiscoworks Common Services2.2
AvayaConverged Communications Server2.0
AvayaSg2004.4
AvayaSg2034.4
AvayaSg208All versions
AvayaSg54.2
AppleMac Os X10.3.3
AppleMac Os X Server10.3.3
FreebsdFreebsd4.8
HpHp-Ux8.05
OpenbsdOpenbsd3.3
RedhatEnterprise Linux3.0
RedhatEnterprise Linux Desktop3.0
RedhatLinux7.2
ScoOpenserver5.0.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-0079?

CVE-2004-0079 is a vulnerability with a CVSS score of 7.5 (HIGH). The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null ...

How severe is CVE-2004-0079?

CVE-2004-0079 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0079?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Firewall Services Module, Hp Aaa Server, Hp Apache-Based Web Server, Symantec Clientless Vpn Gateway 4400, Cisco Ciscoworks Common Management Foundation.