[CVE-2008-0891, CVE-2008-1672] OpenSSL denial of service vulnerabilities (crashes)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
openssl (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
Undecided
|
Jamie Strandboge |
Bug Description
Binary package hint: openssl
CVE-2008-0891 description:
"Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a crafted packet. NOTE: some of these details are obtained from third party information."
http://
CVE-2008-1672 description:
"OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites." "
http://
Upstream advisory: http://
Does this apply to Hardy?
Related branches
Changed in openssl: | |
status: | In Progress → Fix Committed |
See also: http:// cert.fi/ haavoittuvuudet /2008/advisory- openssl. html