CVE-2007-4995: Critical severity OpenSSL OpenSSL vulnerability
Published Oct 13, 2007
·Updated
Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
6 affected components
OpenSSL OpenSSL=0.9.8b
OpenSSL OpenSSL=0.9.8c
OpenSSL OpenSSL=0.9.8e
OpenSSL OpenSSL=0.9.8d
OpenSSL OpenSSL=0.9.8a
OpenSSL OpenSSL=0.9.8
Remediation
Patch Available
Event History
Oct 13, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4995?
CVE-2007-4995 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2007-4995?
To fix CVE-2007-4995, upgrade to OpenSSL version 0.9.8f or later.
3
Who is affected by CVE-2007-4995?
CVE-2007-4995 affects all versions of OpenSSL from 0.9.8 up to, but not including, 0.9.8f.
4
What types of attacks can exploit CVE-2007-4995?
Exploitation of CVE-2007-4995 can lead to arbitrary code execution through DTLS vulnerability.
5
Is CVE-2007-4995 a network-level vulnerability?
Yes, CVE-2007-4995 can be exploited by remote attackers over the network.