Secunia Logo
Netsikker nu! 2008
 
OpenSSL Multiple Vulnerabilities
Secunia Advisory: SA22130
Release Date: 2006-09-28
Last Update: 2007-10-12
Popularity: 22,728 views

Critical:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

Software:OpenSSL 0.9.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-2937
CVE-2006-2940
CVE-2006-3738
CVE-2006-4343
CVE-2007-5135


Description:
Some vulnerabilities have been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.

1) An error in the processing of certain invalid ASN.1 structures can be exploited to cause an infinite loop and consume system memory in an application using OpenSSL to process ASN.1 data from untrusted sources.

NOTE: This does not affect versions prior to 0.9.7.

2) Certain types of public keys take overly long time to process and can be exploited to cause a DoS in an application using OpenSSL to process ASN.1 data from untrusted sources.

3) An error in the "SSL_get_shared_ciphers()" function can be exploited to cause a buffer overflow by sending a list of ciphers to an application using the vulnerable function.

Successful exploitation allows execution of arbitrary code.

4) An error in the SSLv2 client code can be exploited by a malicious server to crash a vulnerable client using OpenSSL to create an SSLv2 connection to the server.

Solution:
OpenSSL 0.9.7 branch:
Update to version 0.9.7m or later.

OpenSSL 0.9.8 branch:
Update to version 0.9.8f or later.

Provided and/or discovered by:
1, 2) Dr. S. N. Henson, Open Network Security
3, 4) Tavis Ormandy and Will Drewry, Google Security Team

Changelog:
2006-09-29: Updated advisory with additional information. Increased criticality. Added links to US-CERT vulnerability notes.
2007-09-28: Updated "Solution" section with additional information about an off-by-one error in "SSL_get_shares_ciphers()" provided by Moritz Jodeit. Updated "Original Advisory" section.
2007-10-01: Added CVE reference.
2007-10-12: Updated "Solution" section. Added link to OpenSSL advisory.

Original Advisory:
http://www.openssl.org/news/secadv_20060928.txt
http://www.openssl.org/news/secadv_20071012.txt

http://archives.neohapsis.com/archives/bugtraq/2007-09/
http://marc.info/?l=openssl-cvs&m=119020417919619&w=2

Other References:
US-CERT VU#247744:
http://www.kb.cert.org/vuls/id/247744

US-CERT VU#386964:
http://www.kb.cert.org/vuls/id/386964

US-CERT VU#423396:
http://www.kb.cert.org/vuls/id/423396

US-CERT VU#547300:
http://www.kb.cert.org/vuls/id/547300


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. noName CMS "index.php" SQL Injection Vulnerabilities // 92 views
2. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 82 views
3. SUSE update for MozillaFirefox // 72 views
4. IBM Lotus Quickr Security Issues and Denial of Service // 64 views
5. D-Bus "_dbus_validate_signature_with_reason()" Denial of Service // 50 views
6. HP-UX NFS/ONCplus Denial of Service Vulnerability // 50 views
7. Debian update for lighttpd // 47 views
8. iseemedia LPViewer ActiveX Control Multiple Buffer Overflow Vulnerabilities // 42 views
9. Kwalbum "UploaditemsPage.php" File Upload Vulnerability // 42 views
10. Fedora update for mediawiki // 41 views