Short Name |
SSL:OPENSSL-ECDH-UAF
|
Severity |
High
|
Recommended |
No
|
Category |
SSL
|
Keywords |
OpenSSL ECDH Use After Free
|
Release Date |
2014/05/05
|
Update Number |
2371
|
Supported Platforms |
idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
SSL: OpenSSL ECDH Use After Free
This signature detects attempts to exploit a known vulnerability against OpenSSL. The vulnerability is due to an error in processing handshake messages arriving in incorrect order by ephemeral ECDH ciphersuites. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted TLS handshake sequence. A successful attack would result in the execution of arbitrary attacker code in the context of the affected application. If the attack fails, the application may terminate abnormally, resulting in a denial-of-service condition. Applications using OpenSSL may be affected by this vulnerability if the version of OpenSSL they use supports ephemeral ECDH ciphersuites and if these ciphersuites are enabled in the application configuration.
Extended Description
OpenSSL is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
OpenSSL 0.9.8 through 0.9.8e and OpenSSL 1.0.0 through 1.0.0d are vulnerable.
Affected Products
- Avaya 96x1 IP Deskphone 6
- HP HP-UX B.11.11
- HP HP-UX B.11.23
- HP HP-UX B.11.31
- HP Insight Control for Linux (IC-Linux) 7.0
- HP System Management Homepage 3.0.0.64
- HP System Management Homepage 3.0.0-68
- HP System Management Homepage 3.0.0.68
- HP System Management Homepage 3.0.1-73
- HP System Management Homepage 3.0.1.73
- HP System Management Homepage 3.0.2-77
- HP System Management Homepage 3.0.2.77
- HP System Management Homepage 3.0.2.77 B
- HP System Management Homepage 6.0
- HP System Management Homepage 6.0.0-95
- HP System Management Homepage 6.0.0.95
- HP System Management Homepage 6.0.0.96
- HP System Management Homepage 6.1
- HP System Management Homepage 6.1.0.102
- HP System Management Homepage 6.1.0-103
- HP System Management Homepage 6.1.0.103
- HP System Management Homepage 6.2
- HP System Management Homepage 6.2
- HP System Management Homepage 6.2.0-12
- HP System Management Homepage 6.2.2.7
- HP System Management Homepage 6.3
- HP System Management Homepage
- Kolab Kolab Groupware Server 2.2.4
- Kolab Kolab Groupware Server 2.3.1
- Kolab Kolab Groupware Server 2.3.2
- Mandriva Linux Mandrake 2010.1
- Mandriva Linux Mandrake 2010.1 X86 64
- Mandriva Linux Mandrake 2011
- Mandriva Linux Mandrake 2011 x86_64
- OpenSSL Project OpenSSL 0.9.8
- OpenSSL Project OpenSSL 0.9.8 A
- OpenSSL Project OpenSSL 0.9.8 B
- OpenSSL Project OpenSSL 0.9.8 C
- OpenSSL Project OpenSSL 0.9.8 D
- OpenSSL Project OpenSSL 0.9.8 E
- OpenSSL Project OpenSSL 0.9.8 F
- OpenSSL Project OpenSSL 0.9.8G
- OpenSSL Project OpenSSL 0.9.8H
- OpenSSL Project OpenSSL 0.9.8I
- OpenSSL Project OpenSSL 0.9.8J
- OpenSSL Project OpenSSL 0.9.8K
- OpenSSL Project OpenSSL 0.9.8L
- OpenSSL Project OpenSSL 0.9.8M
- OpenSSL Project OpenSSL 0.9.8N
- OpenSSL Project OpenSSL 0.9.8O
- OpenSSL Project OpenSSL 0.9.8p
- OpenSSL Project OpenSSL 0.9.8Q
- OpenSSL Project OpenSSL 0.9.8R
- OpenSSL Project OpenSSL 0.9.8s
- OpenSSL Project OpenSSL 1.0.0A
- OpenSSL Project OpenSSL 1.0.0b
- OpenSSL Project OpenSSL 1.0.0c
- OpenSSL Project OpenSSL 1.0.0d
- Ubuntu Ubuntu Linux 10.04 Amd64
- Ubuntu Ubuntu Linux 10.04 ARM
- Ubuntu Ubuntu Linux 10.04 I386
- Ubuntu Ubuntu Linux 10.04 Powerpc
- Ubuntu Ubuntu Linux 10.04 Sparc
- Ubuntu Ubuntu Linux 10.10 amd64
- Ubuntu Ubuntu Linux 10.10 ARM
- Ubuntu Ubuntu Linux 10.10 i386
- Ubuntu Ubuntu Linux 10.10 powerpc
- Ubuntu Ubuntu Linux 11.04 amd64
- Ubuntu Ubuntu Linux 11.04 ARM
- Ubuntu Ubuntu Linux 11.04 i386
- Ubuntu Ubuntu Linux 11.04 powerpc
- Ubuntu Ubuntu Linux 11.10 amd64
- Ubuntu Ubuntu Linux 11.10 i386
- Ubuntu Ubuntu Linux 8.04 LTS Amd64
- Ubuntu Ubuntu Linux 8.04 LTS I386
- Ubuntu Ubuntu Linux 8.04 LTS Lpia
- Ubuntu Ubuntu Linux 8.04 LTS Powerpc
- Ubuntu Ubuntu Linux 8.04 LTS Sparc
References