Lucene search

K
osvGoogleOSV:CVE-2017-3733
HistoryMay 04, 2017 - 7:29 p.m.

CVE-2017-3733

2017-05-0419:29:00
Google
osv.dev
13

AI Score

6.5

Confidence

High

EPSS

0.036

Percentile

91.9%

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.