CVE-2004-0826: Buffer Overflow
Published Sep 2, 2004
·Updated
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
Affected Software
93 affected components
Netscape Enterprise server=3.5
Sun ONE Web Server=4.1
Mozilla Network Security Services=3.6.1
Mozilla Network Security Services=3.2
Netscape Enterprise server=4.0
Sun ONE Web Server=6.0-sp3
Sun ONE Application Server=6.0-sp1
Sun Java System Application Server=7.0
Sun ONE Web Server=6.1
Sun ONE Web Server=6.1-sp1
Netscape Directory Server=4.1
Mozilla Network Security Services=3.7.7
Mozilla Network Security Services=3.7.5
Mozilla Network Security Services=3.7.1
Sun ONE Web Server=4.1-sp11
Netscape Enterprise server=4.1.1
Netscape Enterprise server=3.6
Netscape Enterprise server=4.1-sp8
Netscape Directory Server=1.3-patch5
Sun ONE Application Server=6.0
Mozilla Network Security Services=3.6
Sun ONE Web Server=6.0-sp5
Netscape Enterprise server=3.6
Netscape Directory Server=3.1-patch1
Netscape Enterprise server=2.0a
Mozilla Network Security Services=3.2.1
Sun ONE Web Server=4.1-sp3
Netscape Certificate Server=1.0-patch1
Sun ONE Web Server=4.1-sp1
Netscape Enterprise server=4.1-sp5
Sun Java Enterprise System=2003q4
Netscape Enterprise server=3.0.1b
Netscape Enterprise server=3.0.1
Sun Java System Application Server=7.1
Sun Java Enterprise System=2004q2
Netscape Enterprise server=2.0
Sun ONE Web Server=4.1-sp6
Netscape Enterprise server=3.0.7a
Sun ONE Web Server=6.0-sp7
Sun ONE Web Server=4.1-sp5
Mozilla Network Security Services=3.9
Sun ONE Web Server=6.1-sp2
Mozilla Network Security Services=3.4
Netscape Enterprise server=4.1-sp7
Sun ONE Web Server=4.1-sp14
Sun ONE Web Server=4.1-sp2
Sun ONE Web Server=4.1-sp9
Mozilla Network Security Services=3.8
Sun ONE Web Server=6.0-sp8
Netscape Enterprise server=3.6-sp3
Mozilla Network Security Services=3.4.1
Mozilla Network Security Services=3.7
Netscape Enterprise server=3.6-sp1
Mozilla Network Security Services=3.7.2
Mozilla Network Security Services=3.3
Netscape Enterprise server=3.1
Sun ONE Web Server=4.1-sp8
Mozilla Network Security Services=3.7.3
Netscape Directory Server=3.12
Netscape Enterprise server=3.4
Mozilla Network Security Services=3.4.2
Sun ONE Web Server=4.1-sp7
Sun ONE Web Server=4.1-sp12
Netscape Certificate Server=4.2
Netscape Personalization Engine
Mozilla Network Security Services=3.3.2
Sun Java System Application Server=7.0
Netscape Enterprise server=4.1-sp3
Sun ONE Application Server=6.0-sp2
Netscape Directory Server=4.11
Netscape Enterprise server=2.0.1c
Netscape Enterprise server=3.0
Netscape Enterprise server=3.5
Netscape Enterprise server=5.0
Netscape Enterprise server=4.1-sp4
Mozilla Network Security Services=3.5
Sun Java System Application Server=7.0-ur4
Sun ONE Web Server=4.1-sp13
Sun ONE Web Server=6.0-sp4
Sun ONE Web Server=4.1-sp4
Netscape Enterprise server=3.3
Netscape Directory Server=4.13
Netscape Enterprise server=3.2
Netscape Enterprise server=4.1-sp6
Sun Java System Application Server=7.0
Netscape Enterprise server=3.5.1
Netscape Enterprise server=3.6-sp2
Sun ONE Web Server=4.1-sp10
Mozilla Network Security Services=3.3.1
Netscape Enterprise server=3.0l
HP HP-UX=11.11
HP HP-UX=11.00
HP HP-UX=11.23
Remediation
Patch Available
Patch Available
Event History
Sep 2, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0826?
CVE-2004-0826 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2004-0826?
To fix CVE-2004-0826, update the Netscape Network Security Services library to a patched version.
3
What systems are affected by CVE-2004-0826?
CVE-2004-0826 affects multiple versions of the Netscape Network Security Services library, including versions 3.2 through 3.9.
4
What kind of attack does CVE-2004-0826 allow?
CVE-2004-0826 allows remote attackers to execute arbitrary code on affected systems.
5
When was CVE-2004-0826 disclosed?
CVE-2004-0826 was disclosed in 2004, revealing significant vulnerabilities in SSLv2.