[openssl security] Off-by-one error in the DTLS implementation (CVE-2007-4995)

Bug #153085 reported by Matti Lindell
260
Affects Status Importance Assigned to Milestone
openssl (Ubuntu)
Fix Released
High
Kees Cook
openssl097 (Ubuntu)
Won't Fix
Undecided
Unassigned

Bug Description

Binary package hint: openssl

Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f and 0.9.7 allow remote attackers to execute arbitrary code via unspecified vectors. http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4995.

I couldn't find changelog entry describing CVE-2007-4995 as fixed, so it probably isn't yet.
Gutsy,Feisty,(Edgy) and Dapper are affected.

CVE References

Matti Lindell (mlind)
description: updated
Revision history for this message
Kees Cook (kees) wrote :

Thanks for the report! From what we've been able to tell, nothing is actually using the DTLS implementation yet, which makes this a less critical issue. But we will be releasing updates. :)

Changed in openssl:
assignee: nobody → keescook
status: New → In Progress
Revision history for this message
Scott Kitterman (kitterman) wrote :

0.9.7 has been removed from Gutsy, so that's one less to worry about.

Revision history for this message
Jason Levine (v-launchpad-net-site-masshole-us) wrote :

Is there a plan to release a fix for 6.06 (Dapper)? I've been frustrated by the slowness of security fixes like this making their way to the LTS version of Ubuntu, so I figure I should explicitly ask before naively waiting for a fix to appear...

Revision history for this message
Kees Cook (kees) wrote :

Yes, all releases will get the update. I expect it will be published on Monday.

Kees Cook (kees)
Changed in openssl:
status: In Progress → Fix Committed
Matti Lindell (mlind)
Changed in openssl:
importance: Undecided → High
status: Fix Committed → Fix Released
Revision history for this message
Johan Kiviniemi (ion) wrote :

This still seems to affect hardy.

Revision history for this message
Kees Cook (kees) wrote :

For clarification, hardy is safe now (openssl 0.9.8g)

Revision history for this message
Kees Cook (kees) wrote :

The code in Dapper is very different. At present, there is not intention to fix this for 0.9.7 in Dapper.

Changed in openssl097:
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.