OpenSSL versions before 0.9.7m and 0.9.8e suffer from an off-by-one buffer overflow in SSL_get_shared_ciphers().
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59646/openssl-offbyone.txt
Source: https://packetstormsecurity.com/files/59646/openssl-offbyone.txt.html

