Description
crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Add Link to Facebook Multiple Cross-Site Scripting Vulnerabilities (1.215)
WordPress Plugin BeCustom Cross-Site Request Forgery (1.0.5.2)
WordPress Plugin Powie's WHOIS Domain Check Cross-Site Scripting (0.9.31)
Coppermine Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7186)