CVE-2008-1678
Publication date 10 July 2008
Last updated 24 July 2024
Ubuntu priority
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache2 | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Fixed 2.2.8-1ubuntu0.3
|
|
7.10 gutsy |
Fixed 2.2.4-3ubuntu0.2
|
|
7.04 feisty |
Not affected
|
|
6.06 LTS dapper |
Not affected
|
Notes
Patch details
Package | Patch details |
---|---|
apache2 |