OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
References
Configurations
History
No history.
Information
Published : 2008-05-29 16:32
Updated : 2022-02-02 15:03
NVD link : CVE-2008-1672
Mitre link : CVE-2008-1672
CVE.ORG link : CVE-2008-1672
JSON object : View
Products Affected
canonical
- ubuntu_linux
openssl
- openssl
CWE
CWE-476
NULL Pointer Dereference