Mandrake Linux Security Advisory : openssl (MDKSA-2007:237)

High Nessus Plugin ID 29234


The remote Mandrake Linux host is missing one or more security updates.


A buffer overflow in the DTLS implementation of OpenSSL 0.9.8 could be exploited by attackers to potentially execute arbitrary code. It is questionable as to whether the DTLS support even worked or is used in any applications; as a result this flaw most likely does not affect most Mandriva users.

The updated packages have been patched to correct these issue.


Update the affected packages.

Plugin Details

Severity: High

ID: 29234

File Name: mandrake_MDKSA-2007-237.nasl

Version: $Revision: 1.14 $

Type: local

Published: 2007/12/07

Modified: 2013/06/01

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:lib64openssl0.9.8, p-cpe:/a:mandriva:linux:lib64openssl0.9.8-devel, p-cpe:/a:mandriva:linux:lib64openssl0.9.8-static-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.8, p-cpe:/a:mandriva:linux:libopenssl0.9.8-devel, p-cpe:/a:mandriva:linux:libopenssl0.9.8-static-devel, p-cpe:/a:mandriva:linux:openssl, cpe:/o:mandriva:linux:2007, cpe:/o:mandriva:linux:2007.1, cpe:/o:mandriva:linux:2008.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2007/12/04

Reference Information

CVE: CVE-2007-4995

MDKSA: 2007:237

CWE: 189