Lucene search

K
hackeroneTheyarestoneH1:221789
HistoryApr 18, 2017 - 7:38 a.m.

Internet Bug Bounty: OOB read in TS_OBJ_print_bio() (CVE-2016-2180)

2017-04-1807:38:28
theyarestone
hackerone.com
54

EPSS

0.206

Percentile

96.4%

The function TS_OBJ_print_bio() misuses OBJ_obj2txt(): the return value is
the total length the OID text representation would use and not the amount
of data written. This will result in OOB reads when large OIDs are presented.

refer:
https://www.openssl.org/news/secadv/20160922.txt