suse · CVE-2013-0166

Quick triage

Priority: medium Published: 2021-05-30 13:08:05 UTC Updated: 2026-04-18 19:05:07 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2013-0166 severity moderate: SUSE including 159 source package names (compat-openssl097g-0.9.7g-146.22.25.1, compat-openssl097g-0.9.7g-146.22.29.1, …), 394 product×package rows across 62 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (62 product lines)): Fixed 229, Known Not Affected 165.

Description:

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.

cvelogic Threat Intelligence