Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:novell:suse_linux_enterprise_module_for_web_scripting:12.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "novell:suse_linux_enterprise_module_for_web_scripting",
"extracted_events": [
{
"last_affected": "12.0"
}
]
}
]
}