The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
Weakness Type (CWE)
Vulnerable Products 20
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*
|
— | — |
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*
|
— | — |
|
Debian Debian_Linux
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
|
— | — |
|
Canonical Ubuntu_Linux
cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:*
|
— | — |
|
Canonical Ubuntu_Linux
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*
|
— | — |
|
Canonical Ubuntu_Linux
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
|
— | — |