Description
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
Remediation
References
Related Vulnerabilities
WordPress Plugin Download Manager Cross-Site Scripting (3.2.46)
IBM WebSEAL Incorrect Default Permissions Vulnerability (CVE-2023-38370)
WordPress Plugin Contact Form 'wpcf_easyform_formid' Parameter SQL Injection (2.7.5)
WordPress Plugin Slideshow Gallery LITE Cross-Site Scripting (1.5.3.4)
Mailman Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-6893)