CVE-2003-0544
Last modified
CVE-2003-0544 is a vulnerability of currently unknown severity. OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.. EPSS estimates a 6.17% chance of exploitation in the next 30 days.
Description
OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 0.9.6 |
| Openssl | Openssl | 0.9.7 |
References
- http://www.cert.org/advisories/CA-2003-26.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/380864US Government Resource
- http://www.redhat.com/support/errata/RHSA-2003-291.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-292.htmlPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2003-26.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/380864US Government Resource
- http://www.redhat.com/support/errata/RHSA-2003-291.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2003-292.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0544?
How severe is CVE-2003-0544?
How do I fix CVE-2003-0544?
Are you affected by CVE-2003-0544?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
