HomeCiscoCVE-2004-0112

CVE-2004-0112

UNKNOWN
5.0CVSS
Published: 2004-11-23
Updated: 2025-04-03
AI Analysis

Description

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVSS Metrics

Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector
network
Access Cmplx
low
Auth
none
Confidentiality
none
Integrity
none
Availability
partial
Weaknesses
CWE-125

Metadata

Primary Vendor
CISCO
Published
11/23/2004
Last Modified
4/3/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

cisco : firewall_services_modulecisco : firewall_services_modulecisco : firewall_services_modulecisco : firewall_services_modulecisco : firewall_services_modulehp : aaa_serverhp : apache-based_web_serverhp : apache-based_web_serversymantec : clientless_vpn_gateway_4400cisco : ciscoworks_common_management_foundationcisco : ciscoworks_common_servicesavaya : converged_communications_serveravaya : sg200avaya : sg200avaya : sg203avaya : sg203avaya : sg208avaya : sg208avaya : sg5avaya : sg5avaya : sg5apple : mac_os_xapple : mac_os_x_serverfreebsd : freebsdfreebsd : freebsdfreebsd : freebsdfreebsd : freebsdfreebsd : freebsdfreebsd : freebsdfreebsd : freebsdfreebsd : freebsdhp : hp-uxhp : hp-uxhp : hp-uxhp : hp-uxopenbsd : openbsdopenbsd : openbsdredhat : enterprise_linuxredhat : enterprise_linuxredhat : enterprise_linuxredhat : enterprise_linux_desktopredhat : linuxredhat : linuxredhat : linuxsco : openserversco : openservercisco : ioscisco : ioscisco : ioscisco : ioscisco : ioscisco : ioscisco : ioscisco : ioscisco : ioscisco : ios4d : webstar4d : webstar4d : webstar4d : webstar4d : webstar4d : webstar4d : webstar4d : webstaravaya : intuity_audixavaya : intuity_audixavaya : intuity_audixavaya : intuity_audixavaya : vsuavaya : vsuavaya : vsuavaya : vsuavaya : vsuavaya : vsuavaya : vsuavaya : vsucheckpoint : firewall-1checkpoint : firewall-1checkpoint : firewall-1checkpoint : firewall-1checkpoint : firewall-1checkpoint : provider-1checkpoint : provider-1checkpoint : provider-1checkpoint : provider-1checkpoint : provider-1checkpoint : vpn-1checkpoint : vpn-1checkpoint : vpn-1checkpoint : vpn-1cisco : access_registrarcisco : application_and_content_networking_softwarecisco : css_secure_content_acceleratorcisco : css_secure_content_acceleratorcisco : css11000_content_services_switchcisco : okena_stormwatchcisco : pix_firewallcisco : threat_responsecisco : webnscisco : webnscisco : webnscisco : webnscisco : webnscisco : webnscisco : webnsdell : bsafe_ssl-jdell : bsafe_ssl-jdell : bsafe_ssl-jforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegateforcepoint : stonegatehp : wbemhp : wbemhp : wbemlitespeedtech : litespeed_web_serverneoteris : instant_virtual_extranetneoteris : instant_virtual_extranetneoteris : instant_virtual_extranetneoteris : instant_virtual_extranetneoteris : instant_virtual_extranetnovell : edirectorynovell : edirectorynovell : edirectorynovell : edirectorynovell : edirectorynovell : edirectorynovell : edirectorynovell : edirectorynovell : imanagernovell : imanageropenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslopenssl : opensslredhat : opensslredhat : opensslredhat : opensslredhat : opensslredhat : opensslsgi : propacksgi : propacksgi : propackstonesoft : serverclusterstonesoft : serverclusterstonesoft : stonebeat_fullclusterstonesoft : stonebeat_fullclusterstonesoft : stonebeat_fullclusterstonesoft : stonebeat_fullclusterstonesoft : stonebeat_fullclusterstonesoft : stonebeat_securityclusterstonesoft : stonebeat_securityclusterstonesoft : stonebeat_webclusterstonesoft : stonebeat_webclustertarantella : tarantella_enterprisetarantella : tarantella_enterprisetarantella : tarantella_enterprisevmware : gsx_servervmware : gsx_servervmware : gsx_servervmware : gsx_servervmware : gsx_serveravaya : s8300avaya : s8300avaya : s8500avaya : s8500avaya : s8700avaya : s8700bluecoat : proxysgcisco : call_managercisco : content_services_switch_11500cisco : gss_4480_global_site_selectorcisco : gss_4490_global_site_selectorcisco : mds_9000cisco : secure_content_acceleratorsecurecomputing : sidewindersecurecomputing : sidewindersecurecomputing : sidewindersecurecomputing : sidewindersecurecomputing : sidewindersecurecomputing : sidewindersecurecomputing : sidewindersun : crypto_accelerator_4000bluecoat : cacheos_ca_sabluecoat : cacheos_ca_sacisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_softwarecisco : pix_firewall_software

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2004-0112 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com