security flaw
Published Mar 18, 2004
7.5
HIGHCVSS 3.1
EPSS 9.54%
Description
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
Affected products
No data.
Configuration 1
- n/a
- 1.1.2
- 1.1.3
- 1.1_\(3.005\)
- 2.1_\(0.208\)
- n/a
- 2.0.43.00
- 2.0.43.04
- 5.0
Configuration 2
- 2.1
- 2.2
- 2.0
- 4.4
- 4.31.29
- 4.4
- 4.31.29
- n/a
- 4.4
- 4.2
- 4.3
- 4.4
- 10.3.3
- 10.3.3
- 4.8
- 4.8
- 4.9
- 5.1
- 5.1
- 5.1
- 5.2
- 5.2.1
- 8.05
- 11.00
- 11.11
- 11.23
- 3.3
- 3.4
- 3.0
- 3.0
- 3.0
- 3.0
- 7.2
- 7.3
- 8.0
- 5.0.6
- 5.0.7
Configuration 3
- 4.0
- 5.2
- 5.2.1
- 5.2.2
- 5.2.3
- 5.2.4
- 5.3
- 5.3.1
- n/a
- 5.1.46
- s3210
- s3400
- 5
- 5x
- 100_r2.0.1
- 500
- 2000_r2.0.1
- 5000_r2.0.1
- 7500_r2.0.1
- 10000_r2.0.1
- n/a
- 2.0
- next_generation_fp0
- next_generation_fp1
- next_generation_fp2
- 4.1
- 4.1
- 4.1
- 4.1
- 4.1
- next_generation_fp0
- next_generation_fp1
- next_generation_fp2
- vsx_ng_with_application_intelligence
- n/a
- n/a
- 1.0
- 2.0
- n/a
- 3.2
- 6.2.2_.111
- n/a
- 6.10
- 6.10_b4
- 7.1_0.1.02
- 7.1_0.2.06
- 7.2_0.0.03
- 7.10
- 7.10_.0.06s
- 3.0
- 3.0.1
- 3.1
- a.01.05.08
- a.02.00.00
- a.02.00.01
- 1.0.1
- 1.0.2
- 1.0.3
- 1.1
- 1.1.1
- 1.2.1
- 1.2.2
- 1.2_rc1
- 1.2_rc2
- 1.3
- 1.3.1
- 1.3_rc1
- 1.3_rc2
- 1.3_rc3
- 3.0
- 3.1
- 3.2
- 3.3
- 3.3.1
- 8.0
- 8.5
- 8.5.12a
- 8.5.27
- 8.6.2
- 8.7
- 8.7.1
- 8.7.1
- 1.5
- 2.0
- 0.9.6c
- 0.9.6d
- 0.9.6e
- 0.9.6f
- 0.9.6g
- 0.9.6h
- 0.9.6i
- 0.9.6j
- 0.9.6k
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7a
- 0.9.7b
- 0.9.7c
- 0.9.6-15
- 0.9.6b-3
- 0.9.7a-2
- 0.9.7a-2
- 0.9.7a-2
- 2.3
- 2.4
- 3.0
- 2.5
- 2.5.2
- 1_2.0
- 1_3.0
- 2.0
- 2.5
- 3.0
- 2.0
- 2.5
- 2.0
- 2.5
- 1.5.17
- 1.5.18
- 1.6.2
- 1.6.3
- 1.7
- 1.7.1
- 1.7.2
- 2.0.1
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.1
- 2.2
- 2.2.1
- 2.2.4
- 1.7
- 1.7.2
- 2.0
- 2.0.7
- 2.0.8
- 2.0.9
- 3.20
- 3.30
- 3.40
- 2.0
- 2.0.1_build_2129
- 2.5.1
- 2.5.1_build_5336
- 3.0_build_7592
- r2.0.0
- r2.0.1
- r2.0.0
- r2.0.1
- r2.0.0
- r2.0.1
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- 10000
- 5.2
- 5.2.0.01
- 5.2.0.02
- 5.2.0.03
- 5.2.0.04
- 5.2.1
- 5.2.1.02
- 1.0
- 4.1.10
- 4.1.12
- 6.0
- 6.0\(1\)
- 6.0\(2\)
- 6.0\(3\)
- 6.0\(4\)
- 6.0\(4.101\)
- 6.1
- 6.1\(1\)
- 6.1\(2\)
- 6.1\(3\)
- 6.1\(4\)
- 6.1\(5\)
- 6.2
- 6.2\(1\)
- 6.2\(2\)
- 6.2\(3\)
- 6.2\(3.100\)
- 6.3
- 6.3\(1\)
- 6.3\(2\)
- 6.3\(3.102\)
- 6.3\(3.109\)
No data.
Red Hat Enterprise Linux 3
openssl-0:0.9.7a-33.4
Fixed · RHSA-2004:120
Red Hat Enterprise Linux 3
openssl096b-0:0.9.6b-16
Fixed · RHSA-2004:120
Red Hat Enterprise Linux 3
openssl096b-0:0.9.6b-16.42
Fixed · RHSA-2005:830
Red Hat Enterprise Linux 4
openssl096b-0:0.9.6b-22.42
Fixed · RHSA-2005:830
Red Hat Enterprise Linux AS (Advanced Server) version 2.1
n/a
Fixed · RHSA-2005:829
Red Hat Enterprise Linux ES version 2.1
n/a
Fixed · RHSA-2005:829
Red Hat Enterprise Linux WS version 2.1
n/a
Fixed · RHSA-2005:829
Red Hat Linux 9
n/a
Fixed · RHSA-2004:121
Red Hat Linux Advanced Workstation 2.1
n/a
Fixed · RHSA-2005:829
Red Hat Stronghold 4
n/a
Fixed · RHSA-2004:139
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | openssl-0:0.9.7a-33.4 | Fixed | RHSA-2004:120 |
| Red Hat Enterprise Linux 3 | openssl096b-0:0.9.6b-16 | Fixed | RHSA-2004:120 |
| Red Hat Enterprise Linux 3 | openssl096b-0:0.9.6b-16.42 | Fixed | RHSA-2005:830 |
| Red Hat Enterprise Linux 4 | openssl096b-0:0.9.6b-22.42 | Fixed | RHSA-2005:830 |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | n/a | Fixed | RHSA-2005:829 |
| Red Hat Enterprise Linux ES version 2.1 | n/a | Fixed | RHSA-2005:829 |
| Red Hat Enterprise Linux WS version 2.1 | n/a | Fixed | RHSA-2005:829 |
| Red Hat Linux 9 | n/a | Fixed | RHSA-2004:121 |
| Red Hat Linux Advanced Workstation 2.1 | n/a | Fixed | RHSA-2005:829 |
| Red Hat Stronghold 4 | n/a | Fixed | RHSA-2004:139 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jan 8, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.54% (0.09537) | 95.31th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.54% (0.09537) | 94.82th | v5 (v2026.06.15) |
| Jul 16, 2025 | 2.06% (0.02058) | 83.12th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.67% (0.05674) | 89.45th | v4 (v2025.03.14) |
| Mar 29, 2025 | 13.86% (0.13863) | 90.50th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.95% (0.04948) | 88.92th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.57% (0.00569) | 78.58th | v3 (v2023.03.01) |
| Apr 2, 2024 | 0.57% (0.00569) | 77.43th | v3 (v2023.03.01) |
| Dec 29, 2023 | 0.57% (0.00569) | 75.43th | v3 (v2023.03.01) |
| Sep 24, 2023 | 0.99% (0.00994) | 81.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.94% (0.00944) | 80.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.56% (0.07559) | 92.87th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.56% (0.07559) | 92.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.56% (0.07559) | 81.11th | v2 (v2022.01.01) |
References (49)
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc vendor-advisoryx_refsource_FREEBSDBroken Link
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc vendor-advisoryx_refsource_NETBSDBroken Link
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt vendor-advisoryx_refsource_SCOBroken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834 vendor-advisoryx_refsource_CONECTIVABroken Link
- http://docs.info.apple.com/article.html?artnum=61798 x_refsource_CONFIRMBroken Link
- http://fedoranews.org/updates/FEDORA-2004-095.shtml vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.apple.com/mhonarc/security-announce/msg00045.html x_refsource_CONFIRMBroken Link
- http://marc.info/?l=bugtraq&m=107953412903636&w=2 mailing-listx_refsource_BUGTRAQMailing List
- http://marc.info/?l=bugtraq&m=108403806509920&w=2 vendor-advisoryx_refsource_HPMailing List
- http://secunia.com/advisories/11139 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/17381 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/17398 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/17401 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/18247 third-party-advisoryx_refsource_SECUNIABroken Link
- http://security.gentoo.org/glsa/glsa-200403-03.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm x_refsource_CONFIRMThird Party Advisory
- http://support.lexmark.com/index?page=content&id=TE88&locale=EN&userlocale=EN_US x_refsource_CONFIRMBroken Link
- http://www.ciac.org/ciac/bulletins/o-101.shtml third-party-advisorygovernment-resourcex_refsource_CIACBroken Link
- http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml vendor-advisoryx_refsource_CISCOBroken Link
- http://www.debian.org/security/2004/dsa-465 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.kb.cert.org/vuls/id/288574 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html vendor-advisoryx_refsource_ENGARDEBroken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:023 vendor-advisoryx_refsource_MANDRAKEThird Party Advisory
- http://www.novell.com/linux/security/advisories/2004_07_openssl.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.openssl.org/news/secadv_20040317.txt x_refsource_CONFIRMThird Party Advisory
- http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html vendor-advisoryx_refsource_FEDORAMailing List
- http://www.redhat.com/support/errata/RHSA-2004-120.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2004-121.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2004-139.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-829.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-830.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/9899 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB EntryVendor Advisory
- http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961 vendor-advisoryx_refsource_SLACKWAREBroken Link
- http://www.trustix.org/errata/2004/0012 vendor-advisoryx_refsource_TRUSTIXBroken Link
- http://www.uniras.gov.uk/vuls/2004/224012/index.htm x_refsource_MISCBroken Link
- http://www.us-cert.gov/cas/techalerts/TA04-078A.html third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource
- https://access.redhat.com/security/cve/CVE-2004-0079 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617140 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15505 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2004-0079
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2621 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5770 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A870 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A975 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9779 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2004-0079
Change history (0)
No recorded changes yet.