Lucene search

K
hackeroneTheyarestoneH1:216840
HistoryMar 29, 2017 - 1:24 a.m.

Internet Bug Bounty: OCSP Status Request extension unbounded memory growth (CVE-2016-6304)

2017-03-2901:24:57
theyarestone
hackerone.com
52

0.566 Medium

EPSS

Percentile

97.7%

A malicious client can send an excessively large OCSP Status Request extension.
If that client continually requests renegotiation, sending a large OCSP Status
Request extension each time, then there will be unbounded memory growth on the
server. This will eventually lead to a Denial Of Service attack through memory
exhaustion. Servers with a default configuration are vulnerable even if they do
not support OCSP. Builds using the “no-ocsp” build time option are not affected.