FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-4353

This CVE name corresponds to:

Entered Topic
2014-01-06 openssl -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-4353
Phase Assigned(20130612)

Description

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

References

Source Reference
CONFIRM http://git.openssl.org/gitweb/?p=openssl.git;a=blob_plain;f=CHANGES;hb=refs/heads/OpenSSL_1_0_1-stable
CONFIRM http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=197e0ea817ad64820789d86711d55ff50d71f631
CONFIRM http://www.openssl.org/news/vulnerabilities.html
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=1049058
CONFIRM http://www.splunk.com/view/SP-CAAAMB3
CONFIRM http://www-01.ibm.com/support/docview.wss?uid=isg400001841
CONFIRM http://www-01.ibm.com/support/docview.wss?uid=isg400001843
DEBIAN DSA-2837
REDHAT RHSA-2014:0015
REDHAT RHSA-2014:0041
SUSE openSUSE-SU-2014:0094
SUSE openSUSE-SU-2014:0096
SUSE openSUSE-SU-2014:0099
UBUNTU USN-2079-1