FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

OpenSSL -- NULL pointer dereference / DoS

Affected packages
1.0.1 <= openssl < 1.0.1_12

Details

VuXML ID 1959e847-d4f0-11e3-84b0-0018fe623f2b
Discovery 2014-05-02
Entry 2014-05-03

OpenBSD and David Ramos reports:

Applications that use SSL_MODE_RELEASE_BUFFERS, such as nginx/apache, are prone to a race condition which may allow a remote attacker to crash the current service.

References

CVE Name CVE-2014-0198
URL http://www.openwall.com/lists/oss-security/2014/05/02/5
URL https://rt.openssl.org/Ticket/Display.html?user=guest&pass=guest&id=3321