Ubuntu Security Notice 620-1 – It was discovered that OpenSSL was vulnerable to a double-free when using TLS server extensions. A remote attacker could send a crafted packet and cause a denial of service via application crash in applications linked against OpenSSL. Ubuntu 8.04 LTS does not compile TLS server extensions by default. It was discovered that OpenSSL could dereference a NULL pointer. If a user or automated system were tricked into connecting to a malicious server with particular cipher suites, a remote attacker could cause a denial of service via application crash.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/67692/USN-620-1.txt
Source: https://packetstormsecurity.com/files/67692/Ubuntu-Security-Notice-620-1.html

