OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | Feb 8, 2013 |
| Apple Osx Apache | — | Apply OS X security update 2013-004Upgrade macOS to the latest version | Aug 28, 2015 | Feb 8, 2013 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Feb 8, 2013 |
| Centos_linux | — | Upgrade openssl-staticUpgrade openssl-develUpgrade opensslUpgrade openssl-perl | Dec 1, 2016 | Feb 8, 2013 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Feb 8, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 3, 2014 |
| Freebsd | — | Upgrade FreeBSDUpgrade openssl | Dec 10, 2025 | Apr 2, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Feb 8, 2013 |
| Hpux | — | Update hpuxwsAPACHE.MOD_PERL2 to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate hpuxwsAPACHE.MOD_JK to the latest versionUpdate hpuxwsAPACHE.PHP2 to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate hpuxwsAPACHE.PHP to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate hpuxwsAPACHE.APACHE to the latest versionUpdate hpuxwsAPACHE.MOD_PERL to the latest versionUpdate hpuxwsAPACHE.APACHE2 to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP2 to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate hpuxwsAPACHE.AUTH_LDAP to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate hpuxwsAPACHE.WEBPROXY to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate hpuxwsAPACHE.MOD_JK2 to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-INC to the latest version | Aug 11, 2017 | Feb 8, 2013 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Feb 8, 2013 | Feb 8, 2013 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory5 | Nov 30, 2017 | Feb 8, 2013 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.0.11-0.175.1.7.0.4.0 on Solaris 11.1Upgrade library/security/openssl/openssl-fips-140 to version 1.2-0.175.1.7.0.4.0 on Solaris 11.1 | May 29, 2017 | Feb 8, 2013 |
| Oracle_linux | — | Upgrade openssl-develUpgrade openssl-staticUpgrade opensslUpgrade openssl-perl | May 13, 2016 | Feb 8, 2013 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 7.1R15Update Pulse Connect Secure to version 7.3R6Update Pulse Connect Secure to version 7.4R3Update Pulse Connect Secure to version 7.2R11 | Oct 28, 2020 | Feb 8, 2013 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Feb 5, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 5, 2013 |
| Suse | — | Upgrade compat-openssl097g-32bitUpgrade libopenssl-devel-32bitUpgrade libopenssl0_9_8Upgrade openssl-32bitUpgrade libopenssl1_0_0-32bitUpgrade opensslUpgrade SUSE_SLES_SAP-releaseUpgrade libopenssl1_0_0-debuginfoUpgrade compat-openssl097gUpgrade openssl-devel-64bitUpgrade libopenssl0_9_8-x86Upgrade openssl-docUpgrade libopenssl0_9_8-hmac-32bitUpgrade sle-sdk-releaseUpgrade libopenssl1_0_0-debuginfo-x86Upgrade libopenssl0_9_8-hmac-x86Upgrade libopenssl1_0_0Upgrade libopenssl0_9_8-hmacUpgrade openssl-develUpgrade openssl-debugsourceUpgrade libopenssl1_0_0-debuginfo-32bitUpgrade libopenssl0_9_8-32bitUpgrade openssl-debuginfoUpgrade openssl-x86Upgrade openssl-64bitUpgrade openssl-devel-32bitUpgrade libopenssl-develUpgrade libopenssl1_0_0-x86 | Dec 12, 2013 | Feb 8, 2013 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl0.9.8 | Nov 8, 2024 | Feb 8, 2013 |
| Vmsa 2013 0009 | — | Upgrade VMware ESXi 5.0 to build number 1311175Upgrade VMware ESX 4.1 to build number 1198252Upgrade VMware ESXi 4.1 to build number 1198252Upgrade VMware ESXi 5.1 to build number 1483097 | Aug 9, 2013 | Feb 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub