CVE-2013-4353
Publication date 6 January 2014
Last updated 24 July 2024
Ubuntu priority
The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
openssl098 | ||
Notes
Patch details
Package | Patch details |
---|---|
openssl |
References
Related Ubuntu Security Notices (USN)
- USN-2079-1
- OpenSSL vulnerabilities
- 9 January 2014