SSL: OpenSSL ssl_get_algorithm2 TLS Denial of Service

This signature detects attempts to exploit a known vulnerability in OpenSSL. The vulnerability is due to an error in ssl_get_algorithms2() where the SSL/TLS version is obtained from an incorrect structure leading to a NULL pointer dereference when computing a message digest. A remote unauthenticated attacker can exploit this vulnerability to cause a denial of service condition on applications that use the vulnerable version of the OpenSSL library.

Extended Description

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

Affected Products

Openssl openssl

References

BugTraq: 64530

CVE: CVE-2013-6449

Short Name
SSL:OPENSSL-TLS-DOS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SSL
Keywords
CVE-2013-6449 Denial OpenSSL Service TLS bid:64530 of ssl_get_algorithm2
Release Date
03/20/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3650
False Positive
Unknown
Vendors

Openssl

CVSS Score

4.3

Found a potential security threat?