Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.
2016-03-03T20:59:02.877
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1a | Yes |
Application | openssl | openssl | 1.0.1b | Yes |
Application | openssl | openssl | 1.0.1c | Yes |
Application | openssl | openssl | 1.0.1d | Yes |
Application | openssl | openssl | 1.0.1e | Yes |
Application | openssl | openssl | 1.0.1f | Yes |
Application | openssl | openssl | 1.0.1g | Yes |
Application | openssl | openssl | 1.0.1h | Yes |
Application | openssl | openssl | 1.0.1i | Yes |
Application | openssl | openssl | 1.0.1j | Yes |
Application | openssl | openssl | 1.0.1k | Yes |
Application | openssl | openssl | 1.0.1l | Yes |
Application | openssl | openssl | 1.0.1m | Yes |
Application | openssl | openssl | 1.0.1n | Yes |
Application | openssl | openssl | 1.0.1o | Yes |
Application | openssl | openssl | 1.0.1p | Yes |
Application | openssl | openssl | 1.0.1q | Yes |
Application | openssl | openssl | 1.0.1r | Yes |
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2a | Yes |
Application | openssl | openssl | 1.0.2b | Yes |
Application | openssl | openssl | 1.0.2c | Yes |
Application | openssl | openssl | 1.0.2d | Yes |
Application | openssl | openssl | 1.0.2e | Yes |
Application | openssl | openssl | 1.0.2f | Yes |