MEDIUM · 5.0

CVE-2004-0081

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test T...

Vulnerability Description

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoFirewall Services ModuleAll versions
HpAaa ServerAll versions
HpApache-Based Web Server2.0.43.00
SymantecClientless Vpn Gateway 44005.0
CiscoCiscoworks Common Management Foundation2.1
CiscoCiscoworks Common Services2.2
AvayaConverged Communications Server2.0
AvayaSg2004.4
AvayaSg2034.4
AvayaSg208All versions
AvayaSg54.2
AppleMac Os X10.3.3
AppleMac Os X Server10.3.3
FreebsdFreebsd4.8
HpHp-Ux8.05
OpenbsdOpenbsd3.3
RedhatEnterprise Linux3.0
RedhatEnterprise Linux Desktop3.0
RedhatLinux7.2
ScoOpenserver5.0.6

References

FAQ

What is CVE-2004-0081?

CVE-2004-0081 is a vulnerability with a CVSS score of 5.0 (MEDIUM). OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test T...

How severe is CVE-2004-0081?

CVE-2004-0081 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0081?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Firewall Services Module, Hp Aaa Server, Hp Apache-Based Web Server, Symantec Clientless Vpn Gateway 4400, Cisco Ciscoworks Common Management Foundation.