CVE-2004-0079: Null Pointer Dereference

Published Mar 18, 2004
·
Updated

The dochangecipherspec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

Affected Software

458 affected components
Cisco Firewall Services Module
Cisco Firewall Services Module=1.1.2
Cisco Firewall Services Module=1.1.3
Cisco Firewall Services Module=1.1_\(3.005\)
Cisco Firewall Services Module=2.1_\(0.208\)
HP Aaa Server
HP Apache-based Web Server=2.0.43.00
HP Apache-based Web Server=2.0.43.04
Symantec Clientless VPN Gateway 4400=5.0
Cisco CiscoWorks Common Management Foundation=2.1
Cisco CiscoWorks Common Services=2.2
Avaya Converged Communications Server=2.0
Avaya Sg200=4.4
Avaya Sg200=4.31.29
Avaya Sg203=4.4
Avaya Sg203=4.31.29
Avaya Sg208
Avaya Sg208=4.4
Avaya Sg5=4.2
Avaya Sg5=4.3
Avaya Sg5=4.4
Apple iOS and macOS=10.3.3
Apple Mac OS X Server=10.3.3
FreeBSD FreeBSD=4.8
FreeBSD FreeBSD=4.8-releng
FreeBSD FreeBSD=4.9
FreeBSD FreeBSD=5.1
FreeBSD FreeBSD=5.1-release
FreeBSD FreeBSD=5.1-releng
FreeBSD FreeBSD=5.2
FreeBSD FreeBSD=5.2.1-release
HP HP-UX=8.05
HP HP-UX=11.00
HP HP-UX=11.11
HP HP-UX=11.23
OpenBSD OpenBSD=3.3
OpenBSD OpenBSD=3.4
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux Desktop=3.0
redhat Linux=7.2
redhat Linux=7.3
redhat Linux=8.0
SCO OpenServer=5.0.6
SCO OpenServer=5.0.7
All of the following
Any of the following
Cisco IOS=12.1\(11\)e
Cisco IOS=12.1\(11b\)e
Cisco IOS=12.1\(11b\)e12
Cisco IOS=12.1\(11b\)e14
Cisco IOS=12.1\(13\)e9
Cisco IOS=12.1\(19\)e1
Cisco IOS=12.2\(14\)sy
Cisco IOS=12.2\(14\)sy1
Cisco IOS=12.2sy
Cisco IOS=12.2za
Any of the following
4d WebStar=4.0
4d WebStar=5.2
4d WebStar=5.2.1
4d WebStar=5.2.2
4d WebStar=5.2.3
4d WebStar=5.2.4
4d WebStar=5.3
4d WebStar=5.3.1
Avaya Intuity Audix
Avaya Intuity Audix=5.1.46
Avaya Intuity Audix=s3210
Avaya Intuity Audix=s3400
Avaya Vsu=5
Avaya Vsu=5x
Avaya Vsu=100_r2.0.1
Avaya Vsu=500
Avaya Vsu=2000_r2.0.1
Avaya Vsu=5000_r2.0.1
Avaya Vsu=7500_r2.0.1
Avaya Vsu=10000_r2.0.1
Checkpoint Firewall-1
Checkpoint Firewall-1=2.0
Checkpoint Firewall-1=next_generation_fp0
Checkpoint Firewall-1=next_generation_fp1
Checkpoint Firewall-1=next_generation_fp2
Checkpoint Provider-1=4.1
Checkpoint Provider-1=4.1-sp1
Checkpoint Provider-1=4.1-sp2
Checkpoint Provider-1=4.1-sp3
Checkpoint Provider-1=4.1-sp4
Checkpoint Vpn-1=next_generation_fp0
Checkpoint Vpn-1=next_generation_fp1
Checkpoint Vpn-1=next_generation_fp2
Checkpoint Vpn-1=vsx_ng_with_application_intelligence
Cisco Access Registrar
Cisco Application And Content Networking Software
Cisco Css Secure Content Accelerator=1.0
Cisco Css Secure Content Accelerator=2.0
Cisco Css11000 Content Services Switch
Cisco Okena Stormwatch=3.2
Cisco PIX firewall=6.2.2_.111
Cisco Threat Response
Cisco WebNS=6.10
Cisco WebNS=6.10_b4
Cisco WebNS=7.1_0.1.02
Cisco WebNS=7.1_0.2.06
Cisco WebNS=7.2_0.0.03
Cisco WebNS=7.10
Cisco WebNS=7.10_.0.06s
Dell BSAFE SSL-J=3.0
Dell BSAFE SSL-J=3.0.1
Dell BSAFE SSL-J=3.1
HP Wbem=a.01.05.08
HP Wbem=a.02.00.00
HP Wbem=a.02.00.01
Lite Speed Technologies Litespeed Web Server=1.0.1
Lite Speed Technologies Litespeed Web Server=1.0.2
Lite Speed Technologies Litespeed Web Server=1.0.3
Lite Speed Technologies Litespeed Web Server=1.1
Lite Speed Technologies Litespeed Web Server=1.1.1
Lite Speed Technologies Litespeed Web Server=1.2.1
Lite Speed Technologies Litespeed Web Server=1.2.2
Lite Speed Technologies Litespeed Web Server=1.2_rc1
Lite Speed Technologies Litespeed Web Server=1.2_rc2
Lite Speed Technologies Litespeed Web Server=1.3
Lite Speed Technologies Litespeed Web Server=1.3.1
Lite Speed Technologies Litespeed Web Server=1.3_rc1
Lite Speed Technologies Litespeed Web Server=1.3_rc2
Lite Speed Technologies Litespeed Web Server=1.3_rc3
Neoteris Instant Virtual Extranet=3.0
Neoteris Instant Virtual Extranet=3.1
Neoteris Instant Virtual Extranet=3.2
Neoteris Instant Virtual Extranet=3.3
Neoteris Instant Virtual Extranet=3.3.1
Novell eDirectory=8.0
Novell eDirectory=8.5
Novell eDirectory=8.5.12a
Novell eDirectory=8.5.27
Novell eDirectory=8.6.2
Novell eDirectory=8.7
Novell eDirectory=8.7.1
Novell eDirectory=8.7.1-sp1
Novell iManager=1.5
Novell iManager=2.0
OpenSSL OpenSSL=0.9.6c
OpenSSL OpenSSL=0.9.6d
OpenSSL OpenSSL=0.9.6e
OpenSSL OpenSSL=0.9.6f
OpenSSL OpenSSL=0.9.6g
OpenSSL OpenSSL=0.9.6h
OpenSSL OpenSSL=0.9.6i
OpenSSL OpenSSL=0.9.6j
OpenSSL OpenSSL=0.9.6k
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.7-beta1
OpenSSL OpenSSL=0.9.7-beta2
OpenSSL OpenSSL=0.9.7-beta3
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.7b
OpenSSL OpenSSL=0.9.7c
redhat Openssl=0.9.6-15
redhat Openssl=0.9.6b-3
redhat Openssl=0.9.7a-2
redhat Openssl=0.9.7a-2
redhat Openssl=0.9.7a-2
SGI ProPack=2.3
SGI ProPack=2.4
SGI ProPack=3.0
Stonesoft Servercluster=2.5
Stonesoft Servercluster=2.5.2
Stonesoft Stonebeat Fullcluster=1_2.0
Stonesoft Stonebeat Fullcluster=1_3.0
Stonesoft Stonebeat Fullcluster=2.0
Stonesoft Stonebeat Fullcluster=2.5
Stonesoft Stonebeat Fullcluster=3.0
Stonesoft Stonebeat Securitycluster=2.0
Stonesoft Stonebeat Securitycluster=2.5
Stonesoft Stonebeat Webcluster=2.0
Stonesoft Stonebeat Webcluster=2.5
Stonesoft StoneGate=1.5.17
Stonesoft StoneGate=1.5.18
Stonesoft StoneGate=1.6.2
Stonesoft StoneGate=1.6.3
Stonesoft StoneGate=1.7
Stonesoft StoneGate=1.7.1
Stonesoft StoneGate=1.7.2
Stonesoft StoneGate=2.0.1
Stonesoft StoneGate=2.0.4
Stonesoft StoneGate=2.0.5
Stonesoft StoneGate=2.0.6
Stonesoft StoneGate=2.0.7
Stonesoft StoneGate=2.0.8
Stonesoft StoneGate=2.0.9
Stonesoft StoneGate=2.1
Stonesoft StoneGate=2.2
Stonesoft StoneGate=2.2.1
Stonesoft StoneGate=2.2.4
Stonesoft Stonegate Vpn Client=1.7
Stonesoft Stonegate Vpn Client=1.7.2
Stonesoft Stonegate Vpn Client=2.0
Stonesoft Stonegate Vpn Client=2.0.7
Stonesoft Stonegate Vpn Client=2.0.8
Stonesoft Stonegate Vpn Client=2.0.9
Tarantella Tarantella Enterprise=3.20
Tarantella Tarantella Enterprise=3.30
Tarantella Tarantella Enterprise=3.40
VMware GSX Server=2.0
VMware GSX Server=2.0.1_build_2129
VMware GSX Server=2.5.1
VMware GSX Server=2.5.1_build_5336
VMware GSX Server=3.0_build_7592
Avaya S8300=r2.0.0
Avaya S8300=r2.0.1
Avaya S8500=r2.0.0
Avaya S8500=r2.0.1
Avaya S8700=r2.0.0
Avaya S8700=r2.0.1
bluecoat ProxySG
Cisco Call Manager
Cisco Content Services Switch 11500
Cisco Gss 4480 Global Site Selector
Cisco Gss 4490 Global Site Selector
Cisco MDS 9000
Cisco Secure Content Accelerator=10000
Securecomputing Sidewinder=5.2
Securecomputing Sidewinder=5.2.0.01
Securecomputing Sidewinder=5.2.0.02
Securecomputing Sidewinder=5.2.0.03
Securecomputing Sidewinder=5.2.0.04
Securecomputing Sidewinder=5.2.1
Securecomputing Sidewinder=5.2.1.02
Sun Crypto Accelerator 4000=1.0
bluecoat Cacheos Ca Sa=4.1.10
bluecoat Cacheos Ca Sa=4.1.12
Cisco Pix Firewall Software=6.0
Cisco Pix Firewall Software=6.0\(1\)
Cisco Pix Firewall Software=6.0\(2\)
Cisco Pix Firewall Software=6.0\(3\)
Cisco Pix Firewall Software=6.0\(4\)
Cisco Pix Firewall Software=6.0\(4.101\)
Cisco Pix Firewall Software=6.1
Cisco Pix Firewall Software=6.1\(1\)
Cisco Pix Firewall Software=6.1\(2\)
Cisco Pix Firewall Software=6.1\(3\)
Cisco Pix Firewall Software=6.1\(4\)
Cisco Pix Firewall Software=6.1\(5\)
Cisco Pix Firewall Software=6.2
Cisco Pix Firewall Software=6.2\(1\)
Cisco Pix Firewall Software=6.2\(2\)
Cisco Pix Firewall Software=6.2\(3\)
Cisco Pix Firewall Software=6.2\(3.100\)
Cisco Pix Firewall Software=6.3
Cisco Pix Firewall Software=6.3\(1\)
Cisco Pix Firewall Software=6.3\(2\)
Cisco Pix Firewall Software=6.3\(3.102\)
Cisco Pix Firewall Software=6.3\(3.109\)
Cisco IOS=12.1\(11\)e
Cisco IOS=12.1\(11b\)e
Cisco IOS=12.1\(11b\)e12
Cisco IOS=12.1\(11b\)e14
Cisco IOS=12.1\(13\)e9
Cisco IOS=12.1\(19\)e1
Cisco IOS=12.2\(14\)sy
Cisco IOS=12.2\(14\)sy1
Cisco IOS=12.2sy
Cisco IOS=12.2za
4d WebStar=4.0
4d WebStar=5.2
4d WebStar=5.2.1
4d WebStar=5.2.2
4d WebStar=5.2.3
4d WebStar=5.2.4
4d WebStar=5.3
4d WebStar=5.3.1
Avaya Intuity Audix
Avaya Intuity Audix=5.1.46
Avaya Intuity Audix=s3210
Avaya Intuity Audix=s3400
Avaya Vsu=5
Avaya Vsu=5x
Avaya Vsu=100_r2.0.1
Avaya Vsu=500
Avaya Vsu=2000_r2.0.1
Avaya Vsu=5000_r2.0.1
Avaya Vsu=7500_r2.0.1
Avaya Vsu=10000_r2.0.1
Checkpoint Firewall-1
Checkpoint Firewall-1=2.0
Checkpoint Firewall-1=next_generation_fp0
Checkpoint Firewall-1=next_generation_fp1
Checkpoint Firewall-1=next_generation_fp2
Checkpoint Provider-1=4.1
Checkpoint Provider-1=4.1-sp1
Checkpoint Provider-1=4.1-sp2
Checkpoint Provider-1=4.1-sp3
Checkpoint Provider-1=4.1-sp4
Checkpoint Vpn-1=next_generation_fp0
Checkpoint Vpn-1=next_generation_fp1
Checkpoint Vpn-1=next_generation_fp2
Checkpoint Vpn-1=vsx_ng_with_application_intelligence
Cisco Access Registrar
Cisco Application And Content Networking Software
Cisco Css Secure Content Accelerator=1.0
Cisco Css Secure Content Accelerator=2.0
Cisco Css11000 Content Services Switch
Cisco Okena Stormwatch=3.2
Cisco PIX firewall=6.2.2_.111
Cisco Threat Response
Cisco WebNS=6.10
Cisco WebNS=6.10_b4
Cisco WebNS=7.1_0.1.02
Cisco WebNS=7.1_0.2.06
Cisco WebNS=7.2_0.0.03
Cisco WebNS=7.10
Cisco WebNS=7.10_.0.06s
Dell BSAFE SSL-J=3.0
Dell BSAFE SSL-J=3.0.1
Dell BSAFE SSL-J=3.1
HP Wbem=a.01.05.08
HP Wbem=a.02.00.00
HP Wbem=a.02.00.01
Lite Speed Technologies Litespeed Web Server=1.0.1
Lite Speed Technologies Litespeed Web Server=1.0.2
Lite Speed Technologies Litespeed Web Server=1.0.3
Lite Speed Technologies Litespeed Web Server=1.1
Lite Speed Technologies Litespeed Web Server=1.1.1
Lite Speed Technologies Litespeed Web Server=1.2.1
Lite Speed Technologies Litespeed Web Server=1.2.2
Lite Speed Technologies Litespeed Web Server=1.2_rc1
Lite Speed Technologies Litespeed Web Server=1.2_rc2
Lite Speed Technologies Litespeed Web Server=1.3
Lite Speed Technologies Litespeed Web Server=1.3.1
Lite Speed Technologies Litespeed Web Server=1.3_rc1
Lite Speed Technologies Litespeed Web Server=1.3_rc2
Lite Speed Technologies Litespeed Web Server=1.3_rc3
Neoteris Instant Virtual Extranet=3.0
Neoteris Instant Virtual Extranet=3.1
Neoteris Instant Virtual Extranet=3.2
Neoteris Instant Virtual Extranet=3.3
Neoteris Instant Virtual Extranet=3.3.1
Novell eDirectory=8.0
Novell eDirectory=8.5
Novell eDirectory=8.5.12a
Novell eDirectory=8.5.27
Novell eDirectory=8.6.2
Novell eDirectory=8.7
Novell eDirectory=8.7.1
Novell eDirectory=8.7.1-sp1
Novell iManager=1.5
Novell iManager=2.0
OpenSSL OpenSSL=0.9.6c
OpenSSL OpenSSL=0.9.6d
OpenSSL OpenSSL=0.9.6e
OpenSSL OpenSSL=0.9.6f
OpenSSL OpenSSL=0.9.6g
OpenSSL OpenSSL=0.9.6h
OpenSSL OpenSSL=0.9.6i
OpenSSL OpenSSL=0.9.6j
OpenSSL OpenSSL=0.9.6k
OpenSSL OpenSSL=0.9.7
OpenSSL OpenSSL=0.9.7-beta1
OpenSSL OpenSSL=0.9.7-beta2
OpenSSL OpenSSL=0.9.7-beta3
OpenSSL OpenSSL=0.9.7a
OpenSSL OpenSSL=0.9.7b
OpenSSL OpenSSL=0.9.7c
redhat Openssl=0.9.6-15
redhat Openssl=0.9.6b-3
redhat Openssl=0.9.7a-2
redhat Openssl=0.9.7a-2
redhat Openssl=0.9.7a-2
SGI ProPack=2.3
SGI ProPack=2.4
SGI ProPack=3.0
Stonesoft Servercluster=2.5
Stonesoft Servercluster=2.5.2
Stonesoft Stonebeat Fullcluster=1_2.0
Stonesoft Stonebeat Fullcluster=1_3.0
Stonesoft Stonebeat Fullcluster=2.0
Stonesoft Stonebeat Fullcluster=2.5
Stonesoft Stonebeat Fullcluster=3.0
Stonesoft Stonebeat Securitycluster=2.0
Stonesoft Stonebeat Securitycluster=2.5
Stonesoft Stonebeat Webcluster=2.0
Stonesoft Stonebeat Webcluster=2.5
Stonesoft StoneGate=1.5.17
Stonesoft StoneGate=1.5.18
Stonesoft StoneGate=1.6.2
Stonesoft StoneGate=1.6.3
Stonesoft StoneGate=1.7
Stonesoft StoneGate=1.7.1
Stonesoft StoneGate=1.7.2
Stonesoft StoneGate=2.0.1
Stonesoft StoneGate=2.0.4
Stonesoft StoneGate=2.0.5
Stonesoft StoneGate=2.0.6
Stonesoft StoneGate=2.0.7
Stonesoft StoneGate=2.0.8
Stonesoft StoneGate=2.0.9
Stonesoft StoneGate=2.1
Stonesoft StoneGate=2.2
Stonesoft StoneGate=2.2.1
Stonesoft StoneGate=2.2.4
Stonesoft Stonegate Vpn Client=1.7
Stonesoft Stonegate Vpn Client=1.7.2
Stonesoft Stonegate Vpn Client=2.0
Stonesoft Stonegate Vpn Client=2.0.7
Stonesoft Stonegate Vpn Client=2.0.8
Stonesoft Stonegate Vpn Client=2.0.9
Tarantella Tarantella Enterprise=3.20
Tarantella Tarantella Enterprise=3.30
Tarantella Tarantella Enterprise=3.40
VMware GSX Server=2.0
VMware GSX Server=2.0.1_build_2129
VMware GSX Server=2.5.1
VMware GSX Server=2.5.1_build_5336
VMware GSX Server=3.0_build_7592
Avaya S8300=r2.0.0
Avaya S8300=r2.0.1
Avaya S8500=r2.0.0
Avaya S8500=r2.0.1
Avaya S8700=r2.0.0
Avaya S8700=r2.0.1
bluecoat ProxySG
Cisco Call Manager
Cisco Content Services Switch 11500
Cisco Gss 4480 Global Site Selector
Cisco Gss 4490 Global Site Selector
Cisco MDS 9000
Cisco Secure Content Accelerator=10000
Securecomputing Sidewinder=5.2
Securecomputing Sidewinder=5.2.0.01
Securecomputing Sidewinder=5.2.0.02
Securecomputing Sidewinder=5.2.0.03
Securecomputing Sidewinder=5.2.0.04
Securecomputing Sidewinder=5.2.1
Securecomputing Sidewinder=5.2.1.02
Sun Crypto Accelerator 4000=1.0
bluecoat Cacheos Ca Sa=4.1.10
bluecoat Cacheos Ca Sa=4.1.12
Cisco Pix Firewall Software=6.0
Cisco Pix Firewall Software=6.0\(1\)
Cisco Pix Firewall Software=6.0\(2\)
Cisco Pix Firewall Software=6.0\(3\)
Cisco Pix Firewall Software=6.0\(4\)
Cisco Pix Firewall Software=6.0\(4.101\)
Cisco Pix Firewall Software=6.1
Cisco Pix Firewall Software=6.1\(1\)
Cisco Pix Firewall Software=6.1\(2\)
Cisco Pix Firewall Software=6.1\(3\)
Cisco Pix Firewall Software=6.1\(4\)
Cisco Pix Firewall Software=6.1\(5\)
Cisco Pix Firewall Software=6.2
Cisco Pix Firewall Software=6.2\(1\)
Cisco Pix Firewall Software=6.2\(2\)
Cisco Pix Firewall Software=6.2\(3\)
Cisco Pix Firewall Software=6.2\(3.100\)
Cisco Pix Firewall Software=6.3
Cisco Pix Firewall Software=6.3\(1\)
Cisco Pix Firewall Software=6.3\(2\)
Cisco Pix Firewall Software=6.3\(3.102\)
Cisco Pix Firewall Software=6.3\(3.109\)

Event History

Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2004-0079?

CVE-2004-0079 has a medium severity rating due to its potential for causing denial of service.

2

How do I fix CVE-2004-0079?

To fix CVE-2004-0079, upgrade OpenSSL to version 0.9.7d or later.

3

What systems are affected by CVE-2004-0079?

CVE-2004-0079 affects OpenSSL versions 0.9.6c through 0.9.6k and 0.9.7a through 0.9.7c, as well as various products utilizing these OpenSSL versions.

4

What types of attacks can exploit CVE-2004-0079?

CVE-2004-0079 can be exploited through crafted SSL/TLS handshakes which lead to null dereference, causing service crashes.

5

Is there a workaround for CVE-2004-0079?

There is no recommended workaround for CVE-2004-0079; the best mitigation is to apply the appropriate OpenSSL update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203