CVE-2007-5135
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 16.06% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- openssl/openssl
- Source
- cve@mitre.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-007.txt.asc
- http://lists.apple.com/archives/security-announce//2008/Jul/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
- http://lists.vmware.com/pipermail/security-announce/2008/000002.html
- http://secunia.com/advisories/22130Vendor Advisory
- http://secunia.com/advisories/27012Vendor Advisory
- http://secunia.com/advisories/27021Vendor Advisory
- http://secunia.com/advisories/27031Vendor Advisory
- http://secunia.com/advisories/27051Vendor Advisory
- http://secunia.com/advisories/27078Vendor Advisory
- http://secunia.com/advisories/27097Vendor Advisory
- http://secunia.com/advisories/27186Vendor Advisory
- http://secunia.com/advisories/27205Vendor Advisory
- http://secunia.com/advisories/27217Vendor Advisory
- http://secunia.com/advisories/27229Vendor Advisory
- http://secunia.com/advisories/27330Vendor Advisory
- http://secunia.com/advisories/27394Vendor Advisory
- http://secunia.com/advisories/27851Vendor Advisory
- http://secunia.com/advisories/27870Vendor Advisory
- http://secunia.com/advisories/27961Vendor Advisory
- http://secunia.com/advisories/28368Vendor Advisory
- http://secunia.com/advisories/29242
- http://secunia.com/advisories/30124
- http://secunia.com/advisories/30161
- http://secunia.com/advisories/31308
- http://secunia.com/advisories/31326
- http://secunia.com/advisories/31467
- http://secunia.com/advisories/31489
- http://security.freebsd.org/advisories/FreeBSD-SA-07:08.openssl.asc
- http://security.gentoo.org/glsa/glsa-200710-06.xml
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.