Hide Forgot
If client authentication is used, then a server can crash with a segmentation fault in the event of a DHE ciphersuite being selected and a zero length ClientKeyExchange (CKE) message being sent by the client. This could be exploited in a denial of service attack. This issue affects OpenSSL version 1.0.2, and is fixed in version 1.0.2a. Acknowledgements: Red Hat would like to thank the OpenSSL project for reporting this issue. Upstream acknowledges Matt Caswell of the OpenSSL development team as the original reporter.
Statement: This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 5, 6, and 7.
External References: https://openssl.org/news/secadv_20150319.txt https://access.redhat.com/articles/1384453
Upstream commit: https://git.openssl.org/?p=openssl.git;a=commitdiff;h=b19d8143212ae5fbc9cebfd51c01f802fabccd33