Description
The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.
Remediation
References
Related Vulnerabilities
WordPress Plugin Comment Rating Cross-Site Request Forgery (2.9.20)
WordPress Plugin Font Organizer Cross-Site Scripting (2.1.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5339)
Oracle JRE Incorrect Conversion between Numeric Types Vulnerability (CVE-2022-34169)
WordPress Plugin Contact Form 7 Database Addon-CFDB7 Unspecified Vulnerability (1.2.5.3)