漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenSSL SSLv2 Client_Master_Key远程拒绝服务漏洞
Vulnerability Description
OpenSSL 0.9.6e版本使用断言检测缓冲区溢出攻击而不是较少严重机制溢出攻击。远程攻击者借助致使OpenSSL中止失败断言的某些消息导致服务拒绝(崩溃),正如使用没有正确处理s2_srvr.c的SSLv2 CLIENT_MASTER_KEY消息。
CVSS Information
N/A
Vulnerability Type
N/A