OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
- https://kc.mcafee.com/corporate/index?page=content&id=SB10091
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Samaritin/OSINT
- https://github.com/chnzzh/OpenSSL-CVE-lib
- https://github.com/mawinkler/c1-ws-ansible
- https://github.com/nidhi7598/OPENSSL_1.0.1g_CVE-2014-3568