DEBIAN-CVE-2008-1678
Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 10 Jul 2008, 17:41
Last modified:28 Apr 2026, 20:10
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
10 Jul 2008, 17:41
Published
Vulnerability first disclosed
28 Apr 2026, 20:10
Last Modified
Vulnerability information updated
Description
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Affected Systems
- debian•apache2
< 2.2.8-4 | < 2.2.8-4 | < 2.2.8-4 | < 2.2.8-4