OpenSSL: Denial of service A vulnerability in OpenSSL's handling of TLS handshakes could result in a Denial of Service condition. openssl 2014-02-21 2014-02-21 497838 remote 1.0.1f 1.0.1 1.0.1f

OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general purpose cryptography library.

A flaw in the ssl3_take_mac function can result in a NULL pointer dereference.

A remote attacker could send a specially crafted TLS handshake, resulting in a Denial of Service condition.

There is no known workaround at this time.

All OpenSSL 1.0.1 users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/openssl-1.0.1f"
CVE-2013-4353 BlueKnight BlueKnight