The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.
| Software | From | Fixed in |
|---|---|---|
| openssl / openssl | 1.0.2a | 1.0.2a.x |
| openssl / openssl | 1.0.2b | 1.0.2b.x |
| openssl / openssl | 1.0.2c | 1.0.2c.x |
| openssl / openssl | 1.0.2 | 1.0.2.x |
| openssl / openssl | 1.0.2d | 1.0.2d.x |