CVE Vulnerabilities

CVE-2007-5135

Published: Sep 27, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl0.9.7 (including)0.9.7 (including)
OpensslOpenssl0.9.7-beta1 (including)0.9.7-beta1 (including)
OpensslOpenssl0.9.7-beta2 (including)0.9.7-beta2 (including)
OpensslOpenssl0.9.7-beta3 (including)0.9.7-beta3 (including)
OpensslOpenssl0.9.7-beta4 (including)0.9.7-beta4 (including)
OpensslOpenssl0.9.7-beta5 (including)0.9.7-beta5 (including)
OpensslOpenssl0.9.7-beta6 (including)0.9.7-beta6 (including)
OpensslOpenssl0.9.7a (including)0.9.7a (including)
OpensslOpenssl0.9.7b (including)0.9.7b (including)
OpensslOpenssl0.9.7c (including)0.9.7c (including)
OpensslOpenssl0.9.7d (including)0.9.7d (including)
OpensslOpenssl0.9.7e (including)0.9.7e (including)
OpensslOpenssl0.9.7f (including)0.9.7f (including)
OpensslOpenssl0.9.7g (including)0.9.7g (including)
OpensslOpenssl0.9.7h (including)0.9.7h (including)
OpensslOpenssl0.9.7i (including)0.9.7i (including)
OpensslOpenssl0.9.7j (including)0.9.7j (including)
OpensslOpenssl0.9.7k (including)0.9.7k (including)
OpensslOpenssl0.9.7l (including)0.9.7l (including)
OpensslOpenssl0.9.8 (including)0.9.8 (including)
OpensslOpenssl0.9.8a (including)0.9.8a (including)
OpensslOpenssl0.9.8b (including)0.9.8b (including)
OpensslOpenssl0.9.8c (including)0.9.8c (including)
OpensslOpenssl0.9.8d (including)0.9.8d (including)
OpensslOpenssl0.9.8e (including)0.9.8e (including)
OpensslOpenssl0.9.8f (including)0.9.8f (including)
Red Hat Enterprise Linux 2.1RedHatopenssl-0:0.9.6b-48*
Red Hat Enterprise Linux 3RedHatopenssl-0:0.9.7a-33.24*
Red Hat Enterprise Linux 4RedHatopenssl-0:0.9.7a-43.17.el4_6.1*
Red Hat Enterprise Linux 5RedHatopenssl-0:0.9.8b-8.3.el5_0.2*
OpensslUbuntudapper*
OpensslUbuntudevel*
OpensslUbuntuedgy*
OpensslUbuntufeisty*
OpensslUbuntugutsy*
OpensslUbuntuhardy*
OpensslUbuntuintrepid*
OpensslUbuntujaunty*
OpensslUbuntukarmic*
OpensslUbuntuupstream*
Openssl097Ubuntudapper*
Openssl097Ubuntuedgy*
Openssl097Ubuntufeisty*

References