Description
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
Remediation
References
Related Vulnerabilities
WordPress Plugin Feed Statistics Open Redirect (3.0)
Apache HTTP Server Other Vulnerability (CVE-2000-0505)
WordPress Plugin Easy Contact Form Builder Cross-Site Scripting (1.0)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-2853)
WordPress Plugin Contest Gallery-Photo Contest for WordPress Cross-Site Request Forgery (10.4.1.1)