CVE-2003-0851: Medium severity Cisco IOS vulnerability
Published Nov 6, 2003
·Updated
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
Affected Software
78 affected components
Cisco IOS=12.1\(11\)e
Cisco IOS=12.1\(11b\)e
Cisco IOS=12.2sx
Cisco IOS=12.2sy
Cisco Css11000 Content Services Switch
Cisco PIX firewall=6.2.2_.111
OpenSSL OpenSSL=0.9.6
OpenSSL OpenSSL=0.9.6a
OpenSSL OpenSSL=0.9.6b
OpenSSL OpenSSL=0.9.6c
OpenSSL OpenSSL=0.9.6d
OpenSSL OpenSSL=0.9.6e
OpenSSL OpenSSL=0.9.6f
OpenSSL OpenSSL=0.9.6g
OpenSSL OpenSSL=0.9.6h
OpenSSL OpenSSL=0.9.6i
OpenSSL OpenSSL=0.9.6j
OpenSSL OpenSSL=0.9.6k
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.7b
Cisco Pix Firewall Software=6.0
Cisco Pix Firewall Software=6.0\(1\)
Cisco Pix Firewall Software=6.0\(2\)
Cisco Pix Firewall Software=6.0\(3\)
Cisco Pix Firewall Software=6.0\(4\)
Cisco Pix Firewall Software=6.0\(4.101\)
Cisco Pix Firewall Software=6.1
Cisco Pix Firewall Software=6.1\(1\)
Cisco Pix Firewall Software=6.1\(2\)
Cisco Pix Firewall Software=6.1\(3\)
Cisco Pix Firewall Software=6.1\(4\)
Cisco Pix Firewall Software=6.1\(5\)
Cisco Pix Firewall Software=6.2
Cisco Pix Firewall Software=6.2\(1\)
Cisco Pix Firewall Software=6.2\(2\)
Cisco Pix Firewall Software=6.2\(3\)
Cisco Pix Firewall Software=6.3\(1\)
Cisco Pix Firewall Software=6.3\(3.102\)
All of the following
Any of the following
Cisco IOS=12.1\(11\)e
Cisco IOS=12.1\(11b\)e
Cisco IOS=12.2sx
Cisco IOS=12.2sy
Any of the following
Cisco Css11000 Content Services Switch
Cisco PIX firewall=6.2.2_.111
OpenSSL OpenSSL=0.9.6
OpenSSL OpenSSL=0.9.6a
OpenSSL OpenSSL=0.9.6b
OpenSSL OpenSSL=0.9.6c
OpenSSL OpenSSL=0.9.6d
OpenSSL OpenSSL=0.9.6e
OpenSSL OpenSSL=0.9.6f
OpenSSL OpenSSL=0.9.6g
OpenSSL OpenSSL=0.9.6h
OpenSSL OpenSSL=0.9.6i
OpenSSL OpenSSL=0.9.6j
OpenSSL OpenSSL=0.9.6k
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.7b
Cisco Pix Firewall Software=6.0
Cisco Pix Firewall Software=6.0\(1\)
Cisco Pix Firewall Software=6.0\(2\)
Cisco Pix Firewall Software=6.0\(3\)
Cisco Pix Firewall Software=6.0\(4\)
Cisco Pix Firewall Software=6.0\(4.101\)
Cisco Pix Firewall Software=6.1
Cisco Pix Firewall Software=6.1\(1\)
Cisco Pix Firewall Software=6.1\(2\)
Cisco Pix Firewall Software=6.1\(3\)
Cisco Pix Firewall Software=6.1\(4\)
Cisco Pix Firewall Software=6.1\(5\)
Cisco Pix Firewall Software=6.2
Cisco Pix Firewall Software=6.2\(1\)
Cisco Pix Firewall Software=6.2\(2\)
Cisco Pix Firewall Software=6.2\(3\)
Cisco Pix Firewall Software=6.3\(1\)
Cisco Pix Firewall Software=6.3\(3.102\)
Remediation
Patch Available
Patch Available
Patch Available
Event History
Nov 6, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 1, 2003
Data Sourced
05:00 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0851?
CVE-2003-0851 has a severity rating that indicates it can cause denial of service attacks.
2
How do I fix CVE-2003-0851?
To fix CVE-2003-0851, update OpenSSL to a version that is patched against this vulnerability.
3
What software is affected by CVE-2003-0851?
CVE-2003-0851 affects several versions of OpenSSL along with Cisco IOS and Cisco PIX Firewall.
4
Can CVE-2003-0851 be exploited remotely?
Yes, CVE-2003-0851 can be exploited remotely using malformed ASN.1 sequences.
5
What are the consequences of an exploit of CVE-2003-0851?
Exploitation of CVE-2003-0851 can lead to a crash of the affected service, resulting in a denial of service.