Lucene search

K
hackeroneTheyarestoneH1:221790
HistoryApr 18, 2017 - 7:39 a.m.

Internet Bug Bounty: Certificate message OOB reads (CVE-2016-6306)

2017-04-1807:39:52
theyarestone
hackerone.com
55

EPSS

0.193

Percentile

96.3%

In OpenSSL 1.0.2 and earlier some missing message length checks can result in
OOB reads of up to 2 bytes beyond an allocated buffer. There is a theoretical
DoS risk but this has not been observed in practice on common platforms.

The messages affected are client certificate, client certificate request and
server certificate. As a result the attack can only be performed against
a client or a server which enables client authentication.

refer:
https://www.openssl.org/news/secadv/20160922.txt