First published: Sat Oct 13 2007(Updated: )
Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSL libcrypto | =0.9.8b | |
OpenSSL libcrypto | =0.9.8c | |
OpenSSL libcrypto | =0.9.8e | |
OpenSSL libcrypto | =0.9.8d | |
OpenSSL libcrypto | =0.9.8a | |
OpenSSL libcrypto | =0.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4995 is considered a critical vulnerability due to the potential for remote code execution.
To fix CVE-2007-4995, upgrade to OpenSSL version 0.9.8f or later.
CVE-2007-4995 affects all versions of OpenSSL from 0.9.8 up to, but not including, 0.9.8f.
Exploitation of CVE-2007-4995 can lead to arbitrary code execution through DTLS vulnerability.
Yes, CVE-2007-4995 can be exploited by remote attackers over the network.