Vulnerability Solutions

The Nimsoft Cloud Monitor Periodic Vulnerability Scan checks for the vulnerability below. To see the most recently added vulnerability solutions that are scanned by WatchMouse, go to the Vulnerability Solutions overview

Category: Web Servers Risk factor: Medium Added: 28 Jan 2012
Synopsis:

The remote host may be affected by a denial of service vulnerability.

Description:

According to its banner, the remote web server is running OpenSSL version 1.0.0f. This version has a flaw in the fix for CVE-2011-4108 such that Datagram Transport Layer Security (DTLS) applications that use it are vulnerable to a denial of service attack.

See also:

http://www.openssl.org/news/secadv_20120118.txt
http://www.openssl.org/news/changelog.html

Solution:

Upgrade to OpenSSL 1.0.0g or later.

Risk factor:

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)