CVE-2015-1794

OpenSSL 1.0.2 - Denial of Service via Zero p Value in Anonymous DH ServerKeyExchange

Title source: llm
STIX 2.1

Description

The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.

Scores

EPSS 0.0985
EPSS Percentile 93.1%

Details

CWE
CWE-189
Status published
Products (5)
openssl/openssl 1.0.2
openssl/openssl 1.0.2a
openssl/openssl 1.0.2b
openssl/openssl 1.0.2c
openssl/openssl 1.0.2d
Published Dec 06, 2015
Tracked Since Feb 18, 2026