[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

Denial of service vulnerability in OpenSSL via an invalid key

ID: oval:org.secpod.oval:def:15480Date: (C)2013-09-20   (M)2023-12-07
Class: VULNERABILITYFamily: macos




The host is installed with Apple Mac OS X 10.6 through 10.6.8 or Mac OS X Lion 10.7 through 10.7.5, Mac OS X Mountain Lion 10.8 through 10.8.4 and is prone to denial of service vulnerability.The flaw is present in the OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d, which fails to handle an invalid key. Successful exploitation allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.

Platform:
Apple Mac OS X 10.6
Apple Mac OS X Server 10.6
Apple Mac OS X 10.7
Apple Mac OS X Server 10.7
Apple Mac OS X 10.8
Apple Mac OS X Server 10.8
Reference:
CVE-2013-0166
CVE    1
CVE-2013-0166
CPE    2
cpe:/o:apple:mac_os_x
cpe:/o:apple:mac_os_x_server

© SecPod Technologies