CVE-2008-1678

MEDIUM

Description

Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.

References

http://bugs.gentoo.org/show_bug.cgi?id=222643

http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html

http://marc.info/?l=openssl-dev&m=121060672602371&w=2

http://secunia.com/advisories/31026

http://secunia.com/advisories/31416

http://secunia.com/advisories/32222

http://secunia.com/advisories/34219

http://secunia.com/advisories/35264

http://secunia.com/advisories/38761

http://secunia.com/advisories/42724

http://secunia.com/advisories/42733

http://secunia.com/advisories/44183

http://security.gentoo.org/glsa/glsa-200807-06.xml

http://securityreason.com/securityalert/3981

http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.663049

http://support.apple.com/kb/HT3216

http://svn.apache.org/viewvc?view=rev&revision=654119

http://www.mandriva.com/security/advisories?name=MDVSA-2009:124

http://www.redhat.com/support/errata/RHSA-2009-1075.html

http://www.securityfocus.com/bid/31681

http://www.securityfocus.com/bid/31692

http://www.ubuntu.com/usn/USN-731-1

http://www.vupen.com/english/advisories/2008/2780

https://bugs.edge.launchpad.net/bugs/186339

https://bugs.edge.launchpad.net/bugs/224945

https://bugzilla.redhat.com/show_bug.cgi?id=447268

https://exchange.xforce.ibmcloud.com/vulnerabilities/43948

https://issues.apache.org/bugzilla/show_bug.cgi?id=44975

https://kb.bluecoat.com/index?page=content&id=SA50

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9754

https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.html

Details

Source: MITRE

Published: 2008-07-10

Updated: 2017-09-29

Type: CWE-399

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (14 total)

IDNameProductFamilySeverity
67866Oracle Linux 5 : httpd (ELSA-2009-1075)NessusOracle Linux Local Security Checks
medium
60591Scientific Linux Security Update : httpd on SL5.x i386/x86_64NessusScientific Linux Local Security Checks
medium
45039OpenSSL < 0.9.8m Multiple VulnerabilitiesNessusWeb Servers
critical
44946Slackware 11.0 / 12.0 / 12.1 / 12.2 / 13.0 / current : openssl (SSA:2010-060-02)NessusSlackware Local Security Checks
critical
43753CentOS 5 : httpd (CESA-2009:1075)NessusCentOS Local Security Checks
medium
43042Mandriva Linux Security Advisory : apache (MDVSA-2009:323)NessusMandriva Local Security Checks
high
39910openSUSE Security Update : apache2 (apache2-222)NessusSuSE Local Security Checks
medium
39761Mandriva Linux Security Advisory : apache (MDVSA-2009:124-1)NessusMandriva Local Security Checks
medium
38945RHEL 5 : httpd (RHSA-2009:1075)NessusRed Hat Local Security Checks
medium
36589Ubuntu 6.06 LTS / 7.10 / 8.04 LTS : apache2 vulnerabilities (USN-731-1)NessusUbuntu Local Security Checks
medium
34699openSUSE 10 Security Update : apache2 (apache2-5648)NessusSuSE Local Security Checks
medium
34374Mac OS X Multiple Vulnerabilities (Security Update 2008-007)NessusMacOS X Local Security Checks
critical
33840Fedora 9 : httpd-2.2.9-1.fc9 (2008-6393)NessusFedora Local Security Checks
medium
33473GLSA-200807-06 : Apache: Denial of ServiceNessusGentoo Local Security Checks
medium