CVE-2005-1247: Medium severity Novell Nsure Audit vulnerability
Published Jan 15, 2004
·Updated
webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.
Affected Software
1 affected component
Novell Nsure Audit=1.0.1
Event History
Jan 15, 2004
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Apr 25, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1247?
CVE-2005-1247 is considered a high-severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2005-1247?
To fix CVE-2005-1247, apply the latest patches from Novell for Nsure Audit 1.0.1.
3
What type of attack does CVE-2005-1247 facilitate?
CVE-2005-1247 facilitates a denial of service attack against SSL servers using malformed ASN.1 packets.
4
What versions of Novell Nsure Audit are affected by CVE-2005-1247?
CVE-2005-1247 affects Novell Nsure Audit version 1.0.1.
5
Can CVE-2005-1247 be exploited remotely?
Yes, CVE-2005-1247 can be exploited remotely by attackers sending malformed client certificates to the SSL server.