Description
The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.
Remediation
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2007-0540)
WordPress 2.8.2 Multiple Security Bypass Vulnerabilities (2.0 - 2.8.2)
Apache HTTP Server Out-of-bounds Write Vulnerability (CVE-2004-0488)
WordPress Plugin WP Fastest Cache Directory Traversal (0.9.1.6)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2246)