CVE-2013-0166
Publication date 8 February 2013
Last updated 24 July 2024
Ubuntu priority
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | 14.04 LTS trusty |
Fixed 1.0.1c-4ubuntu4
|
openssl098 | 14.04 LTS trusty |
Fixed 0.9.8o-7ubuntu3.2.14.04.1
|
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-1732-1
- OpenSSL vulnerabilities
- 21 February 2013