Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SSL:OPENSSL-ECDH-UAF

Severity

High

Recommended

No

Category

SSL

Keywords

OpenSSL ECDH Use After Free

Release Date

2014/05/05

Update Number

2371

Supported Platforms

idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SSL: OpenSSL ECDH Use After Free


This signature detects attempts to exploit a known vulnerability against OpenSSL. The vulnerability is due to an error in processing handshake messages arriving in incorrect order by ephemeral ECDH ciphersuites. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted TLS handshake sequence. A successful attack would result in the execution of arbitrary attacker code in the context of the affected application. If the attack fails, the application may terminate abnormally, resulting in a denial-of-service condition. Applications using OpenSSL may be affected by this vulnerability if the version of OpenSSL they use supports ephemeral ECDH ciphersuites and if these ciphersuites are enabled in the application configuration.

Extended Description

OpenSSL is prone to a denial-of-service vulnerability. An attacker can exploit this issue to crash the affected application, denying service to legitimate users. OpenSSL 0.9.8 through 0.9.8e and OpenSSL 1.0.0 through 1.0.0d are vulnerable.

Affected Products

  • Avaya 96x1 IP Deskphone 6
  • HP HP-UX B.11.11
  • HP HP-UX B.11.23
  • HP HP-UX B.11.31
  • HP Insight Control for Linux (IC-Linux) 7.0
  • HP System Management Homepage 3.0.0.64
  • HP System Management Homepage 3.0.0-68
  • HP System Management Homepage 3.0.0.68
  • HP System Management Homepage 3.0.1-73
  • HP System Management Homepage 3.0.1.73
  • HP System Management Homepage 3.0.2-77
  • HP System Management Homepage 3.0.2.77
  • HP System Management Homepage 3.0.2.77 B
  • HP System Management Homepage 6.0
  • HP System Management Homepage 6.0.0-95
  • HP System Management Homepage 6.0.0.95
  • HP System Management Homepage 6.0.0.96
  • HP System Management Homepage 6.1
  • HP System Management Homepage 6.1.0.102
  • HP System Management Homepage 6.1.0-103
  • HP System Management Homepage 6.1.0.103
  • HP System Management Homepage 6.2
  • HP System Management Homepage 6.2
  • HP System Management Homepage 6.2.0-12
  • HP System Management Homepage 6.2.2.7
  • HP System Management Homepage 6.3
  • HP System Management Homepage
  • Kolab Kolab Groupware Server 2.2.4
  • Kolab Kolab Groupware Server 2.3.1
  • Kolab Kolab Groupware Server 2.3.2
  • Mandriva Linux Mandrake 2010.1
  • Mandriva Linux Mandrake 2010.1 X86 64
  • Mandriva Linux Mandrake 2011
  • Mandriva Linux Mandrake 2011 x86_64
  • OpenSSL Project OpenSSL 0.9.8
  • OpenSSL Project OpenSSL 0.9.8 A
  • OpenSSL Project OpenSSL 0.9.8 B
  • OpenSSL Project OpenSSL 0.9.8 C
  • OpenSSL Project OpenSSL 0.9.8 D
  • OpenSSL Project OpenSSL 0.9.8 E
  • OpenSSL Project OpenSSL 0.9.8 F
  • OpenSSL Project OpenSSL 0.9.8G
  • OpenSSL Project OpenSSL 0.9.8H
  • OpenSSL Project OpenSSL 0.9.8I
  • OpenSSL Project OpenSSL 0.9.8J
  • OpenSSL Project OpenSSL 0.9.8K
  • OpenSSL Project OpenSSL 0.9.8L
  • OpenSSL Project OpenSSL 0.9.8M
  • OpenSSL Project OpenSSL 0.9.8N
  • OpenSSL Project OpenSSL 0.9.8O
  • OpenSSL Project OpenSSL 0.9.8p
  • OpenSSL Project OpenSSL 0.9.8Q
  • OpenSSL Project OpenSSL 0.9.8R
  • OpenSSL Project OpenSSL 0.9.8s
  • OpenSSL Project OpenSSL 1.0.0A
  • OpenSSL Project OpenSSL 1.0.0b
  • OpenSSL Project OpenSSL 1.0.0c
  • OpenSSL Project OpenSSL 1.0.0d
  • Ubuntu Ubuntu Linux 10.04 Amd64
  • Ubuntu Ubuntu Linux 10.04 ARM
  • Ubuntu Ubuntu Linux 10.04 I386
  • Ubuntu Ubuntu Linux 10.04 Powerpc
  • Ubuntu Ubuntu Linux 10.04 Sparc
  • Ubuntu Ubuntu Linux 10.10 amd64
  • Ubuntu Ubuntu Linux 10.10 ARM
  • Ubuntu Ubuntu Linux 10.10 i386
  • Ubuntu Ubuntu Linux 10.10 powerpc
  • Ubuntu Ubuntu Linux 11.04 amd64
  • Ubuntu Ubuntu Linux 11.04 ARM
  • Ubuntu Ubuntu Linux 11.04 i386
  • Ubuntu Ubuntu Linux 11.04 powerpc
  • Ubuntu Ubuntu Linux 11.10 amd64
  • Ubuntu Ubuntu Linux 11.10 i386
  • Ubuntu Ubuntu Linux 8.04 LTS Amd64
  • Ubuntu Ubuntu Linux 8.04 LTS I386
  • Ubuntu Ubuntu Linux 8.04 LTS Lpia
  • Ubuntu Ubuntu Linux 8.04 LTS Powerpc
  • Ubuntu Ubuntu Linux 8.04 LTS Sparc

References

  • BugTraq: 49471
  • CVE: CVE-2011-3210

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out