OpenSSL 0.9.8 < 0.9.8zh X509_ATTRIBUTE Memory Leak DoS
Medium Nessus Plugin ID 87219
SynopsisThe remote host is affected by a denial of service vulnerability.
DescriptionAccording to its banner, the remote host is running a version of OpenSSL 0.9.8 prior to 0.9.8zh. It is, therefore, affected by a flaw in the ASN1_TFLG_COMBINE implementation in file tasn_dec.c related to handling malformed X509_ATTRIBUTE structures. A remote attacker can exploit this to cause a memory leak by triggering a decoding failure in a PKCS#7 or CMS application, resulting in a denial of service.
SolutionUpgrade to OpenSSL version 0.9.8zh or later.