Description
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Remediation
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2606)
Apache HTTP Server Other Vulnerability (CVE-1999-0107)
PHP Reliance on Cookies without Validation and Integrity Checking Vulnerability (CVE-2020-7070)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (3.9.1)