CVE Vulnerabilities

CVE-2011-1473

Published: Jun 16, 2012 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-5094. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment

Affected Software

Name Vendor Start Version End Version
Openssl Openssl 0.9.8m (including) 0.9.8m (including)
Openssl Openssl 0.9.8m-beta1 (including) 0.9.8m-beta1 (including)
Openssl Openssl 0.9.8n (including) 0.9.8n (including)
Openssl Openssl 0.9.8o (including) 0.9.8o (including)
Openssl Openssl 0.9.8p (including) 0.9.8p (including)
Openssl Openssl 0.9.8r (including) 0.9.8r (including)
Openssl Openssl 0.9.8s (including) 0.9.8s (including)
Openssl Openssl 0.9.8t (including) 0.9.8t (including)
Openssl Openssl 0.9.8u (including) 0.9.8u (including)
Openssl Openssl 0.9.8v (including) 0.9.8v (including)
Openssl Openssl 0.9.8w (including) 0.9.8w (including)
Openssl Openssl 0.9.8x (including) 0.9.8x (including)
Openssl Ubuntu devel *
Openssl Ubuntu hardy *
Openssl Ubuntu lucid *
Openssl Ubuntu maverick *
Openssl Ubuntu natty *
Openssl Ubuntu oneiric *
Openssl Ubuntu precise *
Openssl Ubuntu quantal *
Openssl098 Ubuntu devel *
Openssl098 Ubuntu oneiric *
Openssl098 Ubuntu precise *
Openssl098 Ubuntu quantal *

References