Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
2016-09-26T19:59:00.157
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2 | Yes |
Application | openssl | openssl | 1.0.2a | Yes |
Application | openssl | openssl | 1.0.2b | Yes |
Application | openssl | openssl | 1.0.2c | Yes |
Application | openssl | openssl | 1.0.2d | Yes |
Application | openssl | openssl | 1.0.2e | Yes |
Application | openssl | openssl | 1.0.2f | Yes |
Application | openssl | openssl | 1.0.2h | Yes |
Application | openssl | openssl | 1.1.0 | Yes |
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1 | Yes |
Application | openssl | openssl | 1.0.1a | Yes |
Application | openssl | openssl | 1.0.1b | Yes |
Application | openssl | openssl | 1.0.1c | Yes |
Application | openssl | openssl | 1.0.1d | Yes |
Application | openssl | openssl | 1.0.1e | Yes |
Application | openssl | openssl | 1.0.1f | Yes |
Application | openssl | openssl | 1.0.1g | Yes |
Application | openssl | openssl | 1.0.1h | Yes |
Application | openssl | openssl | 1.0.1i | Yes |
Application | openssl | openssl | 1.0.1j | Yes |
Application | openssl | openssl | 1.0.1k | Yes |
Application | openssl | openssl | 1.0.1l | Yes |
Application | openssl | openssl | 1.0.1m | Yes |
Application | openssl | openssl | 1.0.1n | Yes |
Application | openssl | openssl | 1.0.1o | Yes |
Application | openssl | openssl | 1.0.1p | Yes |
Application | openssl | openssl | 1.0.1q | Yes |
Application | openssl | openssl | 1.0.1r | Yes |
Application | openssl | openssl | 1.0.1s | Yes |
Application | openssl | openssl | 1.0.1t | Yes |
Application | nodejs | node.js | < 0.10.47 | Yes |
Application | nodejs | node.js | < 0.12.16 | Yes |
Application | nodejs | node.js | < 4.6.0 | Yes |
Application | nodejs | node.js | < 6.7.0 | Yes |
Operating System | novell | suse_linux_enterprise_module_for_web_scripting | 12.0 | Yes |