CVE-2013-4353: OpenSSL
Medium severity, CVSS 4.3. EPSS: 11.9% chance of exploitation in the next 30 days.
The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.
Affected products
- OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only
Published 2014-01-09. Last modified 2026-06-16.