NULL pointer dereference in OpenSSL - CVE-2013-0166
Published: February 8, 2013 / Updated: July 28, 2020
Vulnerability identifier: #VU32724
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0166
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via an invalid key.
Affected software
OpenSSL
SSL for OpenVMS
openssl (Alpine package)
Slackware Linux
SSL for OpenVMS
openssl (Alpine package)
Slackware Linux
How to mitigate CVE-2013-0166
The vendor has issued the following versions to address this vulnerability: 0.9.8y, 1.0.1d.
OpenSSL - addressed in versions 0.9.8y, 1.0.1d
openssl (Alpine package) - update to 1.0.0k-r0
openssl (Alpine package) - update to 1.0.0k-r0
External References
- http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=62e4506a7d4cec1c8e1ff687f6b220f6a62a57c7
- http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=66e8211c0b1347970096e04b18aa52567c325200
- http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=ebc71865f0506a293242bd4aec97cdc7a8ef24b0
- http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html
- http://marc.info/?l=bugtraq&m=136396549913849&w=2
- http://marc.info/?l=bugtraq&m=136432043316835&w=2
- http://marc.info/?l=bugtraq&m=137545771702053&w=2
- http://rhn.redhat.com/errata/RHSA-2013-0587.html
- http://rhn.redhat.com/errata/RHSA-2013-0782.html
- http://rhn.redhat.com/errata/RHSA-2013-0783.html
- http://rhn.redhat.com/errata/RHSA-2013-0833.html
- http://secunia.com/advisories/53623
- http://secunia.com/advisories/55108
- http://secunia.com/advisories/55139
- http://support.apple.com/kb/HT5880
- http://www.debian.org/security/2013/dsa-2621
- http://www.kb.cert.org/vuls/id/737740
- http://www.openssl.org/news/secadv_20130204.txt
- http://www.splunk.com/view/SP-CAAAHXG
- https://bugzilla.redhat.com/show_bug.cgi?id=908052
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18754
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19081
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19360
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19487
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c03883001