CWE
NVD-CWE-Other 125
Advisory Published
Updated

CVE-2004-0112

First published: Thu Mar 18 2004(Updated: )

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

Credit: cve@mitre.org cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Cisco Firewall Services Module
Cisco Firewall Services Module=1.1.2
Cisco Firewall Services Module=1.1.3
Cisco Firewall Services Module=1.1_\(3.005\)
Cisco Firewall Services Module=2.1_\(0.208\)
HP AAA Server
HP Apache-based Web Server=2.0.43.00
HP Apache-based Web Server=2.0.43.04
Symantec Clientless VPN Gateway 4400=5.0
CiscoWorks Common Management Foundation=2.1
Cisco CiscoWorks Common Services=2.2
avaya converged communications server=2.0
Avaya SG200=4.4
Avaya SG200=4.31.29
Avaya SG203=4.4
Avaya SG203=4.31.29
Avaya SG208
Avaya SG208=4.4
Avaya SG5=4.2
Avaya SG5=4.3
Avaya SG5=4.4
macOS Yosemite=10.3.3
Apple Mac OS X Server=10.3.3
FreeBSD FreeBSD=4.8
FreeBSD FreeBSD=4.8-releng
FreeBSD FreeBSD=4.9
FreeBSD FreeBSD=5.1
FreeBSD FreeBSD=5.1-release
FreeBSD FreeBSD=5.1-releng
FreeBSD FreeBSD=5.2
FreeBSD FreeBSD=5.2.1-release
HPE HP-UX=8.05
HPE HP-UX=11.00
HPE HP-UX=11.11
HPE HP-UX=11.23
OpenBSD=3.3
OpenBSD=3.4
Red Hat Enterprise Linux=3.0
Red Hat Enterprise Linux=3.0
Red Hat Enterprise Linux=3.0
redhat enterprise Linux desktop=3.0
Red Hat Linux=7.2
Red Hat Linux=7.3
Red Hat Linux=8.0
Xinuos OpenServer=5.0.6
Xinuos OpenServer=5.0.7
All of
Any of
Cisco IOS=12.1\(11\)e
Cisco IOS=12.1\(11b\)e
Cisco IOS=12.1\(11b\)e12
Cisco IOS=12.1\(11b\)e14
Cisco IOS=12.1\(13\)e9
Cisco IOS=12.1\(19\)e1
Cisco IOS=12.2\(14\)sy
Cisco IOS=12.2\(14\)sy1
Cisco IOS=12.2sy
Cisco IOS=12.2za
Any of
4D WebStar=4.0
4D WebStar=5.2
4D WebStar=5.2.1
4D WebStar=5.2.2
4D WebStar=5.2.3
4D WebStar=5.2.4
4D WebStar=5.3
4D WebStar=5.3.1
Avaya Intuity Audix
Avaya Intuity Audix=5.1.46
Avaya Intuity Audix=s3210
Avaya Intuity Audix=s3400
Avaya VSU=5
Avaya VSU=5x
Avaya VSU=100_r2.0.1
Avaya VSU=500
Avaya VSU=2000_r2.0.1
Avaya VSU=5000_r2.0.1
Avaya VSU=7500_r2.0.1
Avaya VSU=10000_r2.0.1
Check Point FireWall-1
Check Point FireWall-1=2.0
Check Point FireWall-1=next_generation_fp0
Check Point FireWall-1=next_generation_fp1
Check Point FireWall-1=next_generation_fp2
Check Point Provider-1=4.1
Check Point Provider-1=4.1-sp1
Check Point Provider-1=4.1-sp2
Check Point Provider-1=4.1-sp3
Check Point Provider-1=4.1-sp4
Check Point VPN-1=next_generation_fp0
Check Point VPN-1=next_generation_fp1
Check Point VPN-1=next_generation_fp2
Check Point VPN-1=vsx_ng_with_application_intelligence
Cisco Prime Access Registrar
Cisco Application and Content Networking Software
Cisco Secure Content Accelerator=1.0
Cisco Secure Content Accelerator=2.0
Cisco Content Services Switch 11000
Cisco Okena StormWatch=3.2
Cisco PIX 501=6.2.2_.111
Cisco Threat Response
Cisco WebNS=6.10
Cisco WebNS=6.10_b4
Cisco WebNS=7.1_0.1.02
Cisco WebNS=7.1_0.2.06
Cisco WebNS=7.2_0.0.03
Cisco WebNS=7.10
Cisco WebNS=7.10_.0.06s
Dell BSAFE SSL-J=3.0
Dell BSAFE SSL-J=3.0.1
Dell BSAFE SSL-J=3.1
Forcepoint Stonesoft StoneGate=1.5.17
Forcepoint Stonesoft StoneGate=1.5.18
Forcepoint Stonesoft StoneGate=1.6.2
Forcepoint Stonesoft StoneGate=1.6.3
Forcepoint Stonesoft StoneGate=1.7
Forcepoint Stonesoft StoneGate=1.7.1
Forcepoint Stonesoft StoneGate=1.7.2
Forcepoint Stonesoft StoneGate=2.0.1
Forcepoint Stonesoft StoneGate=2.0.4
Forcepoint Stonesoft StoneGate=2.0.5
Forcepoint Stonesoft StoneGate=2.0.6
Forcepoint Stonesoft StoneGate=2.0.7
Forcepoint Stonesoft StoneGate=2.0.8
Forcepoint Stonesoft StoneGate=2.0.9
Forcepoint Stonesoft StoneGate=2.1
Forcepoint Stonesoft StoneGate=2.2
Forcepoint Stonesoft StoneGate=2.2.1
Forcepoint Stonesoft StoneGate=2.2.4
hp wbem=a.01.05.08
hp wbem=a.02.00.00
hp wbem=a.02.00.01
Litespeed Technologies LiteSpeed Web Server=1.0.1
Litespeed Technologies LiteSpeed Web Server=1.0.2
Litespeed Technologies LiteSpeed Web Server=1.0.3
Litespeed Technologies LiteSpeed Web Server=1.1
Litespeed Technologies LiteSpeed Web Server=1.1.1
Litespeed Technologies LiteSpeed Web Server=1.2-rc1
Litespeed Technologies LiteSpeed Web Server=1.2-rc2
Litespeed Technologies LiteSpeed Web Server=1.2.1
Litespeed Technologies LiteSpeed Web Server=1.2.2
Litespeed Technologies LiteSpeed Web Server=1.3
Litespeed Technologies LiteSpeed Web Server=1.3-rc1
Litespeed Technologies LiteSpeed Web Server=1.3-rc2
Litespeed Technologies LiteSpeed Web Server=1.3-rc3
Neoteris Instant Virtual Extranet=3.0
Neoteris Instant Virtual Extranet=3.1
Neoteris Instant Virtual Extranet=3.2
Neoteris Instant Virtual Extranet=3.3
Neoteris Instant Virtual Extranet=3.3.1
Novell Edirectory=8.0
Novell Edirectory=8.5
Novell Edirectory=8.5.12a
Novell Edirectory=8.5.27
Novell Edirectory=8.6.2
Novell Edirectory=8.7
Novell Edirectory=8.7.1
Novell Edirectory=8.7.1-sp1
Novell iManager=1.5
Novell iManager=2.0
OpenSSL libcrypto=0.9.6c
OpenSSL libcrypto=0.9.6d
OpenSSL libcrypto=0.9.6e
OpenSSL libcrypto=0.9.6f
OpenSSL libcrypto=0.9.6g
OpenSSL libcrypto=0.9.6h
OpenSSL libcrypto=0.9.6i
OpenSSL libcrypto=0.9.6j
OpenSSL libcrypto=0.9.6k
OpenSSL libcrypto=0.9.7
OpenSSL libcrypto=0.9.7-beta1
OpenSSL libcrypto=0.9.7-beta2
OpenSSL libcrypto=0.9.7-beta3
OpenSSL libcrypto=0.9.7a
OpenSSL libcrypto=0.9.7b
OpenSSL libcrypto=0.9.7c
Red Hat OpenSSL=0.9.6-15
Red Hat OpenSSL=0.9.6b-3
Red Hat OpenSSL=0.9.7a-2
Red Hat OpenSSL=0.9.7a-2
Red Hat OpenSSL=0.9.7a-2
SGI ProPack=2.3
SGI ProPack=2.4
SGI ProPack=3.0
stonesoft servercluster=2.5
stonesoft servercluster=2.5.2
stonesoft stonebeat fullcluster=1_2.0
stonesoft stonebeat fullcluster=1_3.0
stonesoft stonebeat fullcluster=2.0
stonesoft stonebeat fullcluster=2.5
stonesoft stonebeat fullcluster=3.0
Stonesoft Stonebeat SecurityCluster=2.0
Stonesoft Stonebeat SecurityCluster=2.5
Stonesoft StoneBeat WebCluster=2.0
Stonesoft StoneBeat WebCluster=2.5
Oracle Tarantella Enterprise=3.20
Oracle Tarantella Enterprise=3.30
Oracle Tarantella Enterprise=3.40
VMware GSX Server=2.0
VMware GSX Server=2.0.1_build_2129
VMware GSX Server=2.5.1
VMware GSX Server=2.5.1_build_5336
VMware GSX Server=3.0_build_7592
Avaya S8300=r2.0.0
Avaya S8300=r2.0.1
Avaya S8500=r2.0.0
Avaya S8500=r2.0.1
avaya s8700=r2.0.0
avaya s8700=r2.0.1
Bluecoat ProxySG
Cisco Call Manager
Cisco Content Services Switch 11500
Cisco GSS 4480 Global Site Selector
Cisco GSS 4490 Global Site Selector
Cisco MDS 9000 Series Multilayer Switches
Cisco CSS Secure Content Accelerator=10000
SecureComputing Sidewinder=5.2
SecureComputing Sidewinder=5.2.0.01
SecureComputing Sidewinder=5.2.0.02
SecureComputing Sidewinder=5.2.0.03
SecureComputing Sidewinder=5.2.0.04
SecureComputing Sidewinder=5.2.1
SecureComputing Sidewinder=5.2.1.02
Sun Crypto Accelerator 4000=1.0
Blue Coat CacheOS CA SA=4.1.10
Blue Coat CacheOS CA SA=4.1.12
Cisco PIX Firewall=6.0
Cisco PIX Firewall=6.0\(1\)
Cisco PIX Firewall=6.0\(2\)
Cisco PIX Firewall=6.0\(3\)
Cisco PIX Firewall=6.0\(4\)
Cisco PIX Firewall=6.0\(4.101\)
Cisco PIX Firewall=6.1
Cisco PIX Firewall=6.1\(1\)
Cisco PIX Firewall=6.1\(2\)
Cisco PIX Firewall=6.1\(3\)
Cisco PIX Firewall=6.1\(4\)
Cisco PIX Firewall=6.1\(5\)
Cisco PIX Firewall=6.2
Cisco PIX Firewall=6.2\(1\)
Cisco PIX Firewall=6.2\(2\)
Cisco PIX Firewall=6.2\(3\)
Cisco PIX Firewall=6.2\(3.100\)
Cisco PIX Firewall=6.3
Cisco PIX Firewall=6.3\(1\)
Cisco PIX Firewall=6.3\(2\)
Cisco PIX Firewall=6.3\(3.102\)
Cisco PIX Firewall=6.3\(3.109\)
Cisco IOS=12.1\(11\)e
Cisco IOS=12.1\(11b\)e
Cisco IOS=12.1\(11b\)e12
Cisco IOS=12.1\(11b\)e14
Cisco IOS=12.1\(13\)e9
Cisco IOS=12.1\(19\)e1
Cisco IOS=12.2\(14\)sy
Cisco IOS=12.2\(14\)sy1
Cisco IOS=12.2sy
Cisco IOS=12.2za
4D WebStar=4.0
4D WebStar=5.2
4D WebStar=5.2.1
4D WebStar=5.2.2
4D WebStar=5.2.3
4D WebStar=5.2.4
4D WebStar=5.3
4D WebStar=5.3.1
Avaya Intuity Audix
Avaya Intuity Audix=5.1.46
Avaya Intuity Audix=s3210
Avaya Intuity Audix=s3400
Avaya VSU=5
Avaya VSU=5x
Avaya VSU=100_r2.0.1
Avaya VSU=500
Avaya VSU=2000_r2.0.1
Avaya VSU=5000_r2.0.1
Avaya VSU=7500_r2.0.1
Avaya VSU=10000_r2.0.1
Check Point FireWall-1
Check Point FireWall-1=2.0
Check Point FireWall-1=next_generation_fp0
Check Point FireWall-1=next_generation_fp1
Check Point FireWall-1=next_generation_fp2
Check Point Provider-1=4.1
Check Point Provider-1=4.1-sp1
Check Point Provider-1=4.1-sp2
Check Point Provider-1=4.1-sp3
Check Point Provider-1=4.1-sp4
Check Point VPN-1=next_generation_fp0
Check Point VPN-1=next_generation_fp1
Check Point VPN-1=next_generation_fp2
Check Point VPN-1=vsx_ng_with_application_intelligence
Cisco Prime Access Registrar
Cisco Application and Content Networking Software
Cisco Secure Content Accelerator=1.0
Cisco Secure Content Accelerator=2.0
Cisco Content Services Switch 11000
Cisco Okena StormWatch=3.2
Cisco PIX 501=6.2.2_.111
Cisco Threat Response
Cisco WebNS=6.10
Cisco WebNS=6.10_b4
Cisco WebNS=7.1_0.1.02
Cisco WebNS=7.1_0.2.06
Cisco WebNS=7.2_0.0.03
Cisco WebNS=7.10
Cisco WebNS=7.10_.0.06s
Dell BSAFE SSL-J=3.0
Dell BSAFE SSL-J=3.0.1
Dell BSAFE SSL-J=3.1
hp wbem=a.01.05.08
hp wbem=a.02.00.00
hp wbem=a.02.00.01
Litespeed Technologies LiteSpeed Web Server=1.0.1
Litespeed Technologies LiteSpeed Web Server=1.0.2
Litespeed Technologies LiteSpeed Web Server=1.0.3
Litespeed Technologies LiteSpeed Web Server=1.1
Litespeed Technologies LiteSpeed Web Server=1.1.1
Litespeed Technologies LiteSpeed Web Server=1.2.1
Litespeed Technologies LiteSpeed Web Server=1.2.2
Litespeed Technologies LiteSpeed Web Server=1.2_rc1
Litespeed Technologies LiteSpeed Web Server=1.2_rc2
Litespeed Technologies LiteSpeed Web Server=1.3
Litespeed Technologies LiteSpeed Web Server=1.3.1
Litespeed Technologies LiteSpeed Web Server=1.3_rc1
Litespeed Technologies LiteSpeed Web Server=1.3_rc2
Litespeed Technologies LiteSpeed Web Server=1.3_rc3
Neoteris Instant Virtual Extranet=3.0
Neoteris Instant Virtual Extranet=3.1
Neoteris Instant Virtual Extranet=3.2
Neoteris Instant Virtual Extranet=3.3
Neoteris Instant Virtual Extranet=3.3.1
Novell Edirectory=8.0
Novell Edirectory=8.5
Novell Edirectory=8.5.12a
Novell Edirectory=8.5.27
Novell Edirectory=8.6.2
Novell Edirectory=8.7
Novell Edirectory=8.7.1
Novell Edirectory=8.7.1-sp1
Novell iManager=1.5
Novell iManager=2.0
OpenSSL libcrypto=0.9.6c
OpenSSL libcrypto=0.9.6d
OpenSSL libcrypto=0.9.6e
OpenSSL libcrypto=0.9.6f
OpenSSL libcrypto=0.9.6g
OpenSSL libcrypto=0.9.6h
OpenSSL libcrypto=0.9.6i
OpenSSL libcrypto=0.9.6j
OpenSSL libcrypto=0.9.6k
OpenSSL libcrypto=0.9.7
OpenSSL libcrypto=0.9.7-beta1
OpenSSL libcrypto=0.9.7-beta2
OpenSSL libcrypto=0.9.7-beta3
OpenSSL libcrypto=0.9.7a
OpenSSL libcrypto=0.9.7b
OpenSSL libcrypto=0.9.7c
Red Hat OpenSSL=0.9.6-15
Red Hat OpenSSL=0.9.6b-3
Red Hat OpenSSL=0.9.7a-2
Red Hat OpenSSL=0.9.7a-2
Red Hat OpenSSL=0.9.7a-2
SGI ProPack=2.3
SGI ProPack=2.4
SGI ProPack=3.0
stonesoft servercluster=2.5
stonesoft servercluster=2.5.2
stonesoft stonebeat fullcluster=1_2.0
stonesoft stonebeat fullcluster=1_3.0
stonesoft stonebeat fullcluster=2.0
stonesoft stonebeat fullcluster=2.5
stonesoft stonebeat fullcluster=3.0
Stonesoft Stonebeat SecurityCluster=2.0
Stonesoft Stonebeat SecurityCluster=2.5
Stonesoft StoneBeat WebCluster=2.0
Stonesoft StoneBeat WebCluster=2.5
Stonesoft StoneGate=1.5.17
Stonesoft StoneGate=1.5.18
Stonesoft StoneGate=1.6.2
Stonesoft StoneGate=1.6.3
Stonesoft StoneGate=1.7
Stonesoft StoneGate=1.7.1
Stonesoft StoneGate=1.7.2
Stonesoft StoneGate=2.0.1
Stonesoft StoneGate=2.0.4
Stonesoft StoneGate=2.0.5
Stonesoft StoneGate=2.0.6
Stonesoft StoneGate=2.0.7
Stonesoft StoneGate=2.0.8
Stonesoft StoneGate=2.0.9
Stonesoft StoneGate=2.1
Stonesoft StoneGate=2.2
Stonesoft StoneGate=2.2.1
Stonesoft StoneGate=2.2.4
Oracle Tarantella Enterprise=3.20
Oracle Tarantella Enterprise=3.30
Oracle Tarantella Enterprise=3.40
VMware GSX Server=2.0
VMware GSX Server=2.0.1_build_2129
VMware GSX Server=2.5.1
VMware GSX Server=2.5.1_build_5336
VMware GSX Server=3.0_build_7592
Avaya S8300=r2.0.0
Avaya S8300=r2.0.1
Avaya S8500=r2.0.0
Avaya S8500=r2.0.1
avaya s8700=r2.0.0
avaya s8700=r2.0.1
Bluecoat ProxySG
Cisco Call Manager
Cisco Content Services Switch 11500
Cisco GSS 4480 Global Site Selector
Cisco GSS 4490 Global Site Selector
Cisco MDS 9000 Series Multilayer Switches
Cisco CSS Secure Content Accelerator=10000
SecureComputing Sidewinder=5.2
SecureComputing Sidewinder=5.2.0.01
SecureComputing Sidewinder=5.2.0.02
SecureComputing Sidewinder=5.2.0.03
SecureComputing Sidewinder=5.2.0.04
SecureComputing Sidewinder=5.2.1
SecureComputing Sidewinder=5.2.1.02
Sun Crypto Accelerator 4000=1.0
Blue Coat CacheOS CA SA=4.1.10
Blue Coat CacheOS CA SA=4.1.12
Cisco PIX Firewall=6.0
Cisco PIX Firewall=6.0\(1\)
Cisco PIX Firewall=6.0\(2\)
Cisco PIX Firewall=6.0\(3\)
Cisco PIX Firewall=6.0\(4\)
Cisco PIX Firewall=6.0\(4.101\)
Cisco PIX Firewall=6.1
Cisco PIX Firewall=6.1\(1\)
Cisco PIX Firewall=6.1\(2\)
Cisco PIX Firewall=6.1\(3\)
Cisco PIX Firewall=6.1\(4\)
Cisco PIX Firewall=6.1\(5\)
Cisco PIX Firewall=6.2
Cisco PIX Firewall=6.2\(1\)
Cisco PIX Firewall=6.2\(2\)
Cisco PIX Firewall=6.2\(3\)
Cisco PIX Firewall=6.2\(3.100\)
Cisco PIX Firewall=6.3
Cisco PIX Firewall=6.3\(1\)
Cisco PIX Firewall=6.3\(2\)
Cisco PIX Firewall=6.3\(3.102\)
Cisco PIX Firewall=6.3\(3.109\)

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Frequently Asked Questions

  • What is the severity of CVE-2004-0112?

    CVE-2004-0112 is classified as high severity due to its potential to cause a denial of service by crashing the application.

  • How do I fix CVE-2004-0112?

    To fix CVE-2004-0112, users should upgrade OpenSSL to version 0.9.7d or later, which includes the necessary patches.

  • What systems are affected by CVE-2004-0112?

    CVE-2004-0112 affects various software utilizing OpenSSL versions 0.9.7a, 0.9.7b, and 0.9.7c, particularly those implementing Kerberos ciphersuites.

  • What kind of attacks can exploit CVE-2004-0112?

    An attacker can exploit CVE-2004-0112 by sending a crafted SSL/TLS handshake that triggers a buffer overflow, leading to application crashes.

  • Was CVE-2004-0112 disclosed publicly?

    Yes, CVE-2004-0112 was publicly disclosed on March 17, 2004, and has received considerable attention in the cybersecurity community.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203