Lucene search

K
cve[email protected]CVE-2008-0891
HistoryMay 29, 2008 - 4:32 p.m.

CVE-2008-0891

2008-05-2916:32:00
CWE-189
web.nvd.nist.gov
58
openssl
vulnerability
denial of service
cve-2008-0891
tls
security

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

8.1 High

AI Score

Confidence

High

0.132 Low

EPSS

Percentile

95.6%

Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
opensslopensslMatch0.9.8f
OR
opensslopensslMatch0.9.8g

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

8.1 High

AI Score

Confidence

High

0.132 Low

EPSS

Percentile

95.6%