OpenSSL Anonymous ECDH Handshake NULL Pointer Dereference

Strike ID:
D14-5oe01
CVSS:
4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
False Positive:
f
Variants:
150
Year:
2014

Description

This strike exploits a NULL pointer dereference vulnerability in OpenSSL versions prior to 0.9.8za, 1.0.0m, 1.0.1h. The problem is triggered when using anonymous ECDH cipher suites. A remote attacker could exploit this by impersonating a legal server and responding to a target client with a malicious handshake sequence. The vulnerable application will then terminate due to illegal memory access.

CVE

References

Bid