Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Debian DSA 394-1 Critical ASN.1 Remote Exploit in OpenSSL

debian
Calendar Grey October 13, 2003
Debian Logo
The Debian Security Notice DSA 394-2 presents fixes for ASN.1 faults within OpenSSL, as reported by NISCC.
teve Henson of the OpenSSL core team identified and prepared fixesfor a number of vulnerabilities in the OpenSSL ASN1 code that werediscovered after running a test suite by British...

Summary

Steve Henson of the OpenSSL core team identified and prepared fixes
for a number of vulnerabilities in the OpenSSL ASN1 code that were
discovered after running a test suite by British National
Infrastructure Security Coordination Centre (NISCC).

A bug in OpenSSLs SSL/TLS protocol was also identified which causes
OpenSSL to parse a client certificate from an SSL/TLS client when it
should reject it as a protocol error.

The Common Vulnerabilities and Exposures project identifies the
following problems:

CAN-2003-0543:

Integer overflow in OpenSSL that allows remote attackers to cause a
denial of service (crash) via an SSL client certificate with
certain ASN.1 tag values.

CAN-2003-0544:

OpenSSL does not properly track the number of characters in certain
ASN.1 inputs, which allows remote attackers to cause a denial of
service (crash) via an SSL client certificate that causes OpenSSL
to read past the end of a buffer when the long form is used.

CAN-2003-0545:

Double-free vulnerability a...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl095

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here