CVE-2007-5135
Published Sep 27, 2007
Last updated 6 years ago
Overview
- Description
- Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-189
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45A518E8-21BE-4C5C-B425-410AB1208E9C" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E3AB748-E463-445C-ABAB-4FEDDFD1878B" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "660E4B8D-AABA-4520-BC4D-CF8E76E07C05" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85BFEED5-4941-41BB-93D1-CD5C2A41290E" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9644CC68-1E91-45E7-8C53-1E3FC9976A4E" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B1B98C4-1FFD-4A7C-AA86-A34BC6F7AB31" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7:beta6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73934717-2DA3-4614-A076-D6EDA5EB0626" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78E79A05-64F3-4397-952C-A5BB950C967D" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F7C9E77-1EB2-4720-A8FD-23DC1C877D5A" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "549BB01D-F322-4FE3-BDA2-4FEA8ED8568A" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DE6CBD6-D6DD-4BC5-93F6-FDEA70163336" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98693865-2E79-4BD6-9F89-1994BC9A3E73" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6476506-EC37-4726-82DC-D0E8254A8CDD" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D6ECEF7-CB16-4604-894B-6EB19F1CEF55" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C81EF3D-4DB7-4799-9670-8D79E28CA184" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8116A66-175C-4E6D-9A9B-D54C1D97D213" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "382C1679-DA1D-4FA4-9D5E-B86CC5052D49" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CA28812-8A24-4FE1-BED9-D6D5BB023645" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.7l:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9894D83E-2A27-446E-8B47-9C03CF802A2B" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A4E446D-B9D3-45F2-9722-B41FA14A6C31" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF4EA988-FC80-4170-8933-7C6663731981" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64F8F53B-24A1-4877-B16E-F1917C4E4E81" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75D3ACD5-905F-42BB-BE1A-8382E9D823BF" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "766EA6F2-7FA4-4713-9859-9971CCD2FDCB" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EFBC30B7-627D-48DC-8EF0-AE8FA0C6EDBA" }, { "criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BB38AEA-BAF0-4920-9A71-747C24444770" } ], "operator": "OR" } ] } ]