Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-71263
HistoryAug 26, 2021 - 12:00 a.m.

openssl buffer overflow vulnerability (CNVD-2021-71263)

2021-08-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
15

0.004 Low

EPSS

Percentile

72.1%

OpenSSL is an open source general-purpose cryptographic library from the Openssl team capable of implementing the Secure Sockets Layer (SSLv2/v3) and Secure Transport Layer (TLSv1) protocols. The product supports a variety of encryption algorithms, including symmetric ciphers, hashing algorithms, secure hashing algorithms, etc. openssl suffers from a buffer overflow vulnerability that stems from the product’s assumption that the ASN.1 string uses NULL as a terminator. An attacker could launch an attack by crafting a non-NULL terminated string that could cause an application memory crash or an application crash.