OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
References
Information
Published : 2008-05-29 09:32
Updated : 2022-02-02 07:03
NVD link : CVE-2008-1672
Mitre link : CVE-2008-1672
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
canonical
- ubuntu_linux
openssl
- openssl