View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2007-5135 severity moderate: SUSE including 77 source package names (compat-openssl098, libopenssl-1_0_0-devel, …), 230 product×package rows across 36 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (36 product lines)): Known Not Affected 172, Fixed 58.
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.