OpenSSL v1.0.2.i Release Notes

Release Date: 2016-09-26 // over 7 years ago
    • Missing CRL sanity check

    A bug fix which included a CRL sanity check was added to OpenSSL 1.1.0 but was omitted from OpenSSL 1.0.2i. As a result any attempt to use CRLs in OpenSSL 1.0.2i will crash with a null pointer exception.

    This issue only affects the OpenSSL 1.0.2i [CVE-2016-7052][]

    Matt Caswell