OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses particular cipher suites, which triggers a NULL pointer dereference.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | 0.9.8f (including) | 0.9.8f (including) |
Openssl | Openssl | 0.9.8g (including) | 0.9.8g (including) |
Openssl | Ubuntu | devel | * |
Openssl | Ubuntu | hardy | * |
Openssl | Ubuntu | upstream | * |