Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-1678

Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.091
EPSS Ranking 92.4%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2008-1678
  • Openssl » Openssl » Version: 0.9.8f
    cpe:2.3:a:openssl:openssl:0.9.8f
  • Openssl » Openssl » Version: 0.9.8g
    cpe:2.3:a:openssl:openssl:0.9.8g
  • Openssl » Openssl » Version: 0.9.8h
    cpe:2.3:a:openssl:openssl:0.9.8h


Contact Us

Shodan ® - All rights reserved