The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
Score: 1.5
Priority: P4 - Informational (Low)
Score: 0.02058
Percentile:
0.83128
CVSS v3.1 Score: 7.5
Severity: HIGH