Skip to content
Medium Published: Nov 23, 2004 Modified: Apr 03, 2025

CVE-2004-0112

5 CVSS Score Medium
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
Export CVE-2004-0112 Data:
Share:
Link copied!

Description

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Confidentiality None
Integrity None
Availability P

Affected Software Configurations

  • h cisco firewall_services_module * * * * * * * *
  • h cisco firewall_services_module 1.1.2 * * * * * * *
  • h cisco firewall_services_module 1.1.3 * * * * * * *
  • h cisco firewall_services_module 1.1_\(3.005\) * * * * * * *
  • h cisco firewall_services_module 2.1_\(0.208\) * * * * * * *
  • h hp aaa_server * * * * * * * *
  • h hp apache-based_web_server 2.0.43.00 * * * * * * *
  • h hp apache-based_web_server 2.0.43.04 * * * * * * *
  • h symantec clientless_vpn_gateway_4400 5.0 * * * * * * *
  • a cisco ciscoworks_common_management_foundation 2.1 * * * * * * *

Weaknesses (CWE)

  • CWE-125

References & External Links

CVE History Timeline

Jan 01, 2004 05:00 Initial Analysis
Oct 18, 2016 02:40 CVE Modified
Jul 11, 2017 01:29 CVE Modified
Oct 11, 2017 01:29 CVE Modified
Oct 30, 2018 16:25 CPE Deprecation Remap
Oct 30, 2018 16:25 CPE Deprecation Remap
Oct 30, 2018 16:25 CPE Deprecation Remap
Oct 30, 2018 16:25 CPE Deprecation Remap
Oct 30, 2018 16:25 CPE Deprecation Remap
Oct 30, 2018 16:25 CPE Deprecation Remap