VYPR
Unrated severityNVD Advisory· Published Sep 27, 2007· Updated Jun 16, 2026

CVE-2007-5135

CVE-2007-5135

Description

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

29
  • cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*+ 26 more
    • cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7:beta3:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7:beta4:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7:beta5:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7:beta6:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.7l:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*
    • (no CPE)range: 0.9.7 - 0.9.7l, 0.9.8 - 0.9.8f
  • osv-coords2 versions
    < 1.0.2u-6.2+ 1 more
    • (no CPE)range: < 1.0.2u-6.2
    • (no CPE)range: < 1.1.1l-1.2

Patches

Vulnerability mechanics

References

75

News mentions

0

No linked articles in our index yet.