|
OpenSSL Kerberos Enabled SSLv3 Master Key Exchange Buffer Overflow Vulnerability
A vulnerability has been reported for OpenSSL 0.9.7 pre-release versions. When initiatiating contact between a SSLv3 server, master keys are exchanged between the client and the server. When an oversized master key is supplied to a SSL version 3 server by a malicious client, it may cause a buffer to overflow on the vulnerable system. Execution of arbitrary code as the server process may be possible. This vulnerability is present only when Kerberos is enabled for a system using SSL version 3. |
|
|
Privacy Statement |