Description
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
Remediation
References
Related Vulnerabilities
WordPress Plugin Olevmedia Shortcodes Multiple Cross-Site Scripting Vulnerabilities (1.1.9)
WordPress Plugin WP-Lytebox 'pg' Parameter Local File Inclusion (1.3)
WordPress Plugin Booking.com Product Helper Unspecified Vulnerability (1.0.3)
WordPress Plugin Ldap WP Login/Active Directory Integration Multiple Vulnerabilities (3.0.1)
WordPress Plugin 10Web Social Post Feed Unspecified Vulnerability (1.1.26)