Total vulnerabilities in the database
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
Software | From | Fixed in |
---|---|---|
openssl / openssl | 1.1.0c | 1.1.0c.x |
openssl / openssl | 1.1.0b | 1.1.0b.x |
openssl / openssl | 1.1.0d | 1.1.0d.x |
openssl / openssl | 1.1.0 | 1.1.0.x |
openssl / openssl | 1.1.0a | 1.1.0a.x |
hp / operations_agent | 11.15 | 11.15.x |
hp / operations_agent | 11.14 | 11.14.x |