Description
The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero.
Remediation
References
Related Vulnerabilities
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.17)
WordPress Plugin Contact Form Email Cross-Site Scripting (1.1.49)
WordPress Plugin Social Hashtags Cross-Site Scripting (3.0.0)
WordPress Plugin YouTube Advanced by Embed Plus Cross-Site Scripting (5.3)
Oracle Database Server CVE-2019-2799 Vulnerability (CVE-2019-2799)