Description
The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.
Remediation
References
Related Vulnerabilities
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.32)
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2015-1399)
WordPress Plugin WP Socializer-Simple & Easy Social Media Share Icons Cross-Site Scripting (7.2)
WordPress Plugin Yoast SEO Cross-Site Scripting (2.1.1)
Oracle Database Server CVE-2011-0816 Vulnerability (CVE-2011-0816)