CVE Database
/

CVE-2013-0166

Back to search

CVE-2013-0166

Published: Feb 8, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2013:0587
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:19360
vdb-entry
signature
x_refsource_OVAL
55139
third-party-advisory
x_refsource_SECUNIA
HPSBUX02856
vendor-advisory
x_refsource_HP
SSRT101289
vendor-advisory
x_refsource_HP
openSUSE-SU-2016:0640
vendor-advisory
x_refsource_SUSE
SSRT101108
vendor-advisory
x_refsource_HP
RHSA-2013:0833
vendor-advisory
x_refsource_REDHAT
53623
third-party-advisory
x_refsource_SECUNIA
VU#737740
third-party-advisory
x_refsource_CERT-VN
HPSBUX02909
vendor-advisory
x_refsource_HP
DSA-2621
vendor-advisory
x_refsource_DEBIAN
RHSA-2013:0783
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2013-09-12-1
vendor-advisory
x_refsource_APPLE
55108
third-party-advisory
x_refsource_SECUNIA
RHSA-2013:0782
vendor-advisory
x_refsource_REDHAT
HPSBOV02852
vendor-advisory
x_refsource_HP
SSRT101104
vendor-advisory
x_refsource_HP
SUSE-SU-2015:0578
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:19487
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:18754
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:19081
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now