OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | Feb 8, 2013 |
| Apple Osx Apache | — | Apply OS X security update 2013-004Upgrade macOS to the latest version | Aug 28, 2015 | Feb 8, 2013 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Feb 8, 2013 |
| Centos_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-static | Dec 1, 2016 | Feb 8, 2013 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Feb 8, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 3, 2014 |
| Freebsd | — | Upgrade opensslUpgrade FreeBSD | Dec 10, 2025 | Apr 2, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Feb 8, 2013 |
| Hpux | — | Update hpuxwsAPACHE.APACHE2 to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest version | Aug 11, 2017 | Feb 8, 2013 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 8, 2013 | Feb 8, 2013 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory5 | Nov 30, 2017 | Feb 8, 2013 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.0.11-0.175.1.7.0.4.0 on Solaris 11.1Upgrade library/security/openssl/openssl-fips-140 to version 1.2-0.175.1.7.0.4.0 on Solaris 11.1 | May 29, 2017 | Feb 8, 2013 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-static | May 13, 2016 | Feb 8, 2013 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 7.3R6Update Pulse Connect Secure to version 7.2R11Update Pulse Connect Secure to version 7.4R3Update Pulse Connect Secure to version 7.1R15 | Oct 28, 2020 | Feb 8, 2013 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Feb 5, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 5, 2013 |
| Suse | — | Upgrade libopenssl-develUpgrade libopenssl0_9_8-32bitUpgrade libopenssl0_9_8Upgrade SUSE_SLES_SAP-releaseUpgrade sle-sdk-releaseUpgrade libopenssl1_0_0-debuginfoUpgrade openssl-devel-64bitUpgrade libopenssl1_0_0-32bitUpgrade opensslUpgrade openssl-docUpgrade compat-openssl097gUpgrade libopenssl0_9_8-x86Upgrade openssl-32bitUpgrade libopenssl0_9_8-hmac-32bitUpgrade libopenssl1_0_0Upgrade openssl-debuginfoUpgrade compat-openssl097g-32bitUpgrade openssl-x86Upgrade libopenssl1_0_0-debuginfo-32bitUpgrade libopenssl1_0_0-debuginfo-x86Upgrade libopenssl1_0_0-x86Upgrade libopenssl0_9_8-hmac-x86Upgrade libopenssl-devel-32bitUpgrade libopenssl0_9_8-hmacUpgrade openssl-develUpgrade openssl-devel-32bitUpgrade openssl-64bitUpgrade openssl-debugsource | Dec 12, 2013 | Feb 8, 2013 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl0.9.8 | Nov 8, 2024 | Feb 8, 2013 |
| Vmsa 2013 0009 | — | Upgrade VMware ESX 4.1 to build number 1198252Upgrade VMware ESXi 4.1 to build number 1198252Upgrade VMware ESXi 5.1 to build number 1483097Upgrade VMware ESXi 5.0 to build number 1311175 | Aug 9, 2013 | Feb 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub