The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-12-23 14:55
Updated : 2018-10-09 12:34
NVD link : CVE-2013-6449
Mitre link : CVE-2013-6449
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
openssl
- openssl