Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-101997
HistoryDec 17, 2021 - 12:00 a.m.

OpenSSL Memory Error Vulnerability

2021-12-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
12

0.002 Low

EPSS

Percentile

57.0%

OpenSSL is a powerful Secure Sockets Layer cryptographic library that includes all major cryptographic algorithms, commonly used keys, certificate wrapper management functions and SSL protocols, and provides rich applications for testing and other purposes. libssl implements the SSL v2/v3 and TLS v1 protocols. A memory error vulnerability exists in OpenSSL version 3.0.0. The vulnerability is due to a call to the X509_verify_cert() function by libssl to verify a server-provided certificate, which is incorrectly handled by OpenSSL. An attacker could exploit this vulnerability to cause a program to fail to run correctly, which could, for example, result in a crash, infinite loop, or other similar error response.

CPENameOperatorVersion
openssl project openssleq3.0.0