crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
2016-09-26T19:59:07.533
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | novell | suse_linux_enterprise_module_for_web_scripting | 12.0 | Yes |
Application | openssl | openssl | 1.0.2i | Yes |
Application | nodejs | node.js | ≤ 4.1.2 | Yes |
Application | nodejs | node.js | < 4.6.0 | Yes |
Application | nodejs | node.js | < 6.7.0 | Yes |