CVE-2004-0112 describes a denial-of-service vulnerability in OpenSSL versions 0.9.7a, 0.9.7b, and 0.9.7c, specifically impacting the SSL/TLS handshaking code when using Kerberos ciphersuites. This flaw, due to improper length checking of Kerberos tickets, allows remote attackers to trigger an out-of-bounds read and crash affected systems, including products from vendors like Apple, Cisco, and Red Hat. The vulnerability has a CVSS score of 5.0, indicating a low-complexity attack requiring no authentication, leading to a partial availability impact. While there is no evidence of active exploitation, nor readily available exploit code in Metasploit or ExploitDB, the CVE has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:*:*:*:*:*:*:*:* | ||
1.1.2CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:1.1.2:*:*:*:*:*:*:* | ||
1.1.3CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:1.1.3:*:*:*:*:*:*:* | ||
1.1_\(3.005\)CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:1.1_\(3.005\):*:*:*:*:*:*:* | ||
2.1_\(0.208\)CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:2.1_\(0.208\):*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.