CVE-2011-4619
Vulnerability Summary
Timeline
Description
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
CVSS Metrics
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 3.16%• Percentile: 87%
Techniques & Countermeasures
- CWE-399•Resource Management Errors
Weaknesses in this category are related to improper management of system resources.
Affected Systems
- Unknown•OpenSSL
≤ 0.9.8r | 0.9.1c | 0.9.2b | 0.9.4 | 0.9.5 | 0.9.5a | 0.9.6 | 0.9.6a | 0.9.6b | 0.9.6c | 0.9.6d | 0.9.6e | 0.9.6f | 0.9.6g | 0.9.6h | 0.9.6h:bogus | 0.9.6i | 0.9.6j | 0.9.6k | 0.9.6l | 0.9.6m | 0.9.7 | 0.9.7a | 0.9.7b | 0.9.7c | 0.9.7d | 0.9.7e | 0.9.7f | 0.9.7g | 0.9.7h | 0.9.7i | 0.9.7j | 0.9.7k | 0.9.7l | 0.9.7m | 0.9.8 | 0.9.8a | 0.9.8b | 0.9.8c | 0.9.8d | 0.9.8e | 0.9.8f | 0.9.8g | 0.9.8h | 0.9.8i | 0.9.8j | 0.9.8k | 0.9.8l | 0.9.8m | 0.9.8n | 0.9.8o | 0.9.8p | 0.9.8q | ≤ 1.0.0e | 1.0.0 | 1.0.0:beta1 | 1.0.0:beta2 | 1.0.0:beta3 | 1.0.0:beta4 | 1.0.0:beta5 | 1.0.0a | 1.0.0b | 1.0.0c | 1.0.0d
References (22)
- http://secunia.com/advisories/48528
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00017.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:006
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.html
- http://www.openssl.org/news/secadv_20120104.txt
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00018.html
- http://rhn.redhat.com/errata/RHSA-2012-1308.html
- http://rhn.redhat.com/errata/RHSA-2012-1307.html
- http://support.apple.com/kb/HT5784
- http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
- http://www.kb.cert.org/vuls/id/737740
- http://marc.info/?l=bugtraq&m=132750648501816&w=2
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:007
- http://rhn.redhat.com/errata/RHSA-2012-1306.html
- http://marc.info/?l=bugtraq&m=134039053214295&w=2
- http://secunia.com/advisories/57353
- http://marc.info/?l=bugtraq&m=133728068926468&w=2
- http://marc.info/?l=bugtraq&m=133951357207000&w=2
- http://www.debian.org/security/2012/dsa-2390
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory3.asc