Skip to main content

OpenSSL TLS Handshake Null Pointer Exception Vulnerability

Last Update Date: 8 Jan 2014 17:40 Release Date: 8 Jan 2014 3241 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in OpenSSL. A remote user can cause denial of service conditions.

 

A remote server can send specially crafted TLS handshake data to trigger a null pointer exception and cause the target client to crash.


Impact

  • Denial of Service

System / Technologies affected

  • Versions prior to 1.0.1f

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (1.0.1f).

Vulnerability Identifier


Source


Related Link