Description
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2008-0340 Vulnerability (CVE-2008-0340)
WordPress Plugin OAuth Single Sign On-SSO (OAuth Client) Cross-Site Scripting (6.20.2)
WordPress 3.8.x Cross-Domain Flash Injection Vulnerability (3.8 - 3.8.24)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2097)