OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
| Software | From | Fixed in |
|---|---|---|
| openssl / openssl | 0.9.8g | 0.9.8g.x |
| openssl / openssl | 0.9.8f | 0.9.8f.x |
| canonical / ubuntu_linux | 8.04 | 8.04.x |