A vulnerability in OpenSSL could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted system. An exploit could trigger an out-of-bounds read condition, causing the system to crash and resulting in a DoS condition. An attacker could exploit this vulnerability by using a malicious server that is designed to submit crafted parameters for a Diffie-Hellman Key Exchange (DHE) or Elliptic Curve DHE (ECDHE) A successful exploit could allow the attacker to access sensitive private key information.”]
Source: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170130-openssl