.:[ packet storm ]:.
                               
plan for the worst
plan for the worst

 ///  File Name:USN-620-1.txt
Description:
Ubuntu Security Notice 620-1 - It was discovered that OpenSSL was vulnerable to a double-free when using TLS server extensions. A remote attacker could send a crafted packet and cause a denial of service via application crash in applications linked against OpenSSL. Ubuntu 8.04 LTS does not compile TLS server extensions by default. It was discovered that OpenSSL could dereference a NULL pointer. If a user or automated system were tricked into connecting to a malicious server with particular cipher suites, a remote attacker could cause a denial of service via application crash.
Homepage:http://security.ubuntu.com/
File Size:6008
Related CVE(s):CVE-2008-0891, CVE-2008-1672
Last Modified:Jun 26 12:09:36 2008
MD5 Checksum:e3d8ad2ad350589c4ffb1f35b0d2da37

 .:. Back