CVE-2013-0166: OpenSSL
Medium severity, CVSS 5.0. EPSS: 19.7% chance of exploitation in the next 30 days.
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
Affected products
- OpenSSL OpenSSL: version 0.9.1c only; version 0.9.2b only; version 0.9.3 only; version 0.9.3a only; version 0.9.4 only; version 0.9.5 only; …
- Red Hat OpenSSL: version 0.9.6-15 only; version 0.9.6b-3 only; version 0.9.7a-2 only
Published 2013-02-08. Last modified 2026-06-16.