Bugzilla – Bug 922503
VUL-1: CVE-2015-1787: openssl: [1.0.2 only] Empty CKE with client auth and DHE
Last modified: 2015-03-19 14:14:34 UTC
We don't ship openssl 1.0.2. (Factory has 1.0.1k)
bugbot adjusting priority
http://openssl.org/news/secadv_20150319.txt Empty CKE with client auth and DHE (CVE-2015-1787) ================================================== Severity: Moderate If client auth is used then a server can seg fault in the event of a DHE ciphersuite being selected and a zero length ClientKeyExchange message being sent by the client. This could be exploited in a DoS attack. This issue affects OpenSSL version: 1.0.2 OpenSSL 1.0.2 users should upgrade to 1.0.2a. This issue was discovered and the fix was developed by Matt Caswell of the OpenSSL development team.
we did not ship 1.0.2 yet, so are not affected.