Back

MEDIUM

openssl: crash with SRP ciphersuite in Server Hello message

Published Aug 13, 2014

Description

The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 5, 6 and 7, Red Hat Enterprise Virtualization 3, and Red Hat Enterprise Storage 2, as they do not enable Secure Remote Password (SRP) support. All other supported Red Hat products that include openssl use older versions that are not affected by this issue.

Metrics

References (51)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Aug 13, 2014
Updated Aug 6, 2024
Reserved Jul 30, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 6, 2014