View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2013-0166 severity moderate: SUSE including 159 source package names (compat-openssl097g-0.9.7g-146.22.25.1, compat-openssl097g-0.9.7g-146.22.29.1, …), 394 product×package rows across 62 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (62 product lines)): Fixed 229, Known Not Affected 165.
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.